duplicate-customer-finder
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs read-only operations using the Shopify Admin API to query customer data for the purpose of deduplication.
- [DATA_EXFILTRATION]: Although the skill accesses customer PII (email, phone, name), it does so within the scope of its stated purpose. Data is processed in-memory and written to a local CSV file, with no evidence of unauthorized external transmission.
- [COMMAND_EXECUTION]: No shell commands, subprocess calls, or external scripts are executed by the skill.
- [PROMPT_INJECTION]: The instructions do not contain any patterns intended to bypass safety guidelines, override agent behavior, or extract system prompts.
Audit Metadata