shopify-admin-referral-source-attribution
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's functionality is limited to read-only GraphQL queries for Shopify order data, as specified in the frontmatter and workflow steps.
- [SAFE]: No malicious code patterns, data exfiltration attempts, hardcoded credentials, or unauthorized persistence mechanisms were detected.
- [PROMPT_INJECTION]: Although the skill processes external strings (referrer URLs and UTM parameters), it does not pipe this data into execution sinks such as shell commands or code evaluation tools, effectively mitigating the risk of indirect prompt injection.
Audit Metadata