shopify-admin-referral-source-attribution

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's functionality is limited to read-only GraphQL queries for Shopify order data, as specified in the frontmatter and workflow steps.
  • [SAFE]: No malicious code patterns, data exfiltration attempts, hardcoded credentials, or unauthorized persistence mechanisms were detected.
  • [PROMPT_INJECTION]: Although the skill processes external strings (referrer URLs and UTM parameters), it does not pipe this data into execution sinks such as shell commands or code evaluation tools, effectively mitigating the risk of indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 10:05 AM
Security Audit — agent-trust-hub — shopify-admin-referral-source-attribution