shopify-admin-metafield-definition-audit
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements read-only logic using the Shopify Admin GraphQL API to audit metafield definitions. It does not perform any mutations or data modifications.
- [SAFE]: No unauthorized network requests or data exfiltration patterns were detected; communication is restricted to the official Shopify platform.
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface by processing external metafield metadata. \n- Ingestion points: Metafield names and descriptions from the Shopify API (SKILL.md). \n- Boundary markers: No delimiters or ignore instructions are used for processed data. \n- Capability inventory: Local CSV file generation and console output. \n- Sanitization: No specific filtering or validation of the retrieved metadata is performed before reporting.
Audit Metadata