shopify-admin-cross-sell-opportunity-finder

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary purpose is data analysis of Shopify orders and products. All operations are read-only GraphQL queries focused on identifying sales patterns.
  • [DATA_EXFILTRATION]: The skill interacts with Shopify store data (orders and customer IDs). However, this access is restricted to the intended business purpose of conversion optimization, and there are no instructions to exfiltrate this data to unauthorized external servers.
  • [COMMAND_EXECUTION]: The skill uses the shopify-admin and shopify-admin-execution toolkits. These are used strictly for API communication with the Shopify platform as defined in the GraphQL operations sections.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources (Shopify orders). While this represents a potential ingestion surface for untrusted data (e.g., product titles or customer metadata), the skill lacks dangerous capabilities such as shell execution or file system writes that could be exploited via injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 10:05 AM
Security Audit — agent-trust-hub — shopify-admin-cross-sell-opportunity-finder