# validate_theme_codeblocks

Validate JS/TS code with Shopify components

Agent View of the PolicyLayer registry record for `validate_theme_codeblocks`. HTML page: https://policylayer.com/tools/shopify/validate-theme-codeblocks

## Facts

- Tool: `validate_theme_codeblocks`
- Server: Shopify Dev (`@Shopify/dev-mcp`) — https://policylayer.com/tools/shopify.md
- Install: `npx -y @Shopify/dev-mcp`
- Homepage: https://github.com/Shopify/dev-mcp
- Risk category: Read (Low risk)
- Registry record: grade B, identity verified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Allowed

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "validate_theme_codeblocks",
    "arguments": {}
  }
}
```

## Why validate_theme_codeblocks is rated Low

This tool performs static validation of code blocks, which is a read-only operation that checks syntax and compatibility without executing, modifying, or deleting any data. The tool returns validation results but does not change state or run arbitrary code. The risk profile is low since validation is purely informational and has no side effects.

From the tool's own definition: "Tool description states it 'Validate[s] JS/TS code' - validation is a checking/verification operation with no modification or execution of code. The verb 'validate' indicates inspection and analysis rather than execution, creation, or deletion."

## Use case

AI agents call validate_theme_codeblocks to retrieve information from Shopify Dev without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Shopify Dev:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "validate_theme_codeblocks": {}
  }
}
```

## Other tools on Shopify Dev (5)

- `fetch_full_docs` — Read — https://policylayer.com/tools/shopify/fetch-full-docs.md
- `introspect_admin_schema` — Read — https://policylayer.com/tools/shopify/introspect-admin-schema.md
- `learn_shopify_api` — Read — https://policylayer.com/tools/shopify/learn-shopify-api.md
- `search_docs_chunks` — Read — https://policylayer.com/tools/shopify/search-docs-chunks.md
- `validate_graphql_codeblocks` — Read — https://policylayer.com/tools/shopify/validate-graphql-codeblocks.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=shopify · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/shopify
