shopify-admin-metafield-definition-audit

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements read-only logic using the Shopify Admin GraphQL API to audit metafield definitions. It does not perform any mutations or data modifications.
  • [SAFE]: No unauthorized network requests or data exfiltration patterns were detected; communication is restricted to the official Shopify platform.
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface by processing external metafield metadata. \n- Ingestion points: Metafield names and descriptions from the Shopify API (SKILL.md). \n- Boundary markers: No delimiters or ignore instructions are used for processed data. \n- Capability inventory: Local CSV file generation and console output. \n- Sanitization: No specific filtering or validation of the retrieved metadata is performed before reporting.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 10:05 AM
Security Audit — agent-trust-hub — shopify-admin-metafield-definition-audit