Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThe skill is developed by Shopify and uses official Shopify resources for theme development tasks. It is generally safe but contains a minor security risk related to indirect prompt injection. The skill instructs the agent to validate generated code by passing it as a string to a shell command, which could be exploited to execute arbitrary commands if the generated code is crafted to break out of shell quoting.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 1 issue
ZeroLeaks
passScore: 93/100 · 2 sections analyzed