weaverse-hydrogen
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Shopify Storefront API and external endpoints, creating a potential ingestion surface for indirect prompt injection. 1. Ingestion points: Loader functions in component sections (e.g., sections/) ingest data from external APIs. 2. Boundary markers: The examples do not show explicit delimiters or 'ignore' instructions for separating external data from prompts. 3. Capability inventory: Includes network operations (fetchWithCache) and command execution for storefront deployment. 4. Sanitization: No explicit sanitization of API-returned data is shown before interpolation into React component props.
- [COMMAND_EXECUTION]: Documentation provides instructions for using CLI tools such as
shopify hydrogen deployand running Node.js scripts for search and documentation retrieval, which are standard development and deployment activities for the framework. - [EXTERNAL_DOWNLOADS]: The skill references and downloads configuration and library components from recognized vendor resources, including weaverse.io and official Weaverse GitHub repositories.
- [DYNAMIC_EXECUTION]: The skill uses dangerouslySetInnerHTML to apply user-configured theme settings as CSS variables and employs dynamic schema registration that isolates validation logic to development environments for performance optimization.
Audit Metadata