shopify-admin-payout-reconciliation

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is strictly read-only and explicitly limits its scope to GraphQL queries for payouts and order transactions. No mutation operations or dangerous administrative actions are performed.
  • [DATA_EXFILTRATION]: No evidence of data exfiltration was found. All data processing occurs within the context of the Shopify Admin environment using standard toolkit operations. There are no external network calls to non-whitelisted domains.
  • [PROMPT_INJECTION]: The instructions do not contain any patterns attempting to override agent behavior, bypass safety filters, or extract system prompts. The logic is focused entirely on the reconciliation workflow.
  • [COMMAND_EXECUTION]: The skill does not attempt to execute arbitrary shell commands. While it mentions the Shopify CLI in the prerequisites, it is documented as a manual setup step for the user rather than an automated script execution within the skill.
  • [OBFUSCATION]: The content is written in clear, human-readable Markdown and standard GraphQL. No hidden characters, Base64 encoding of commands, or homoglyph substitutions were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 10:05 AM
Security Audit — agent-trust-hub — shopify-admin-payout-reconciliation