shopify-admin-return-reason-analysis
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is strictly limited to read-only GraphQL queries (
returns:query,orders:query) via theshopify-admintoolkit. It does not perform any mutations or data-modifying operations on the Shopify store. - [SAFE]: No obfuscated content, hidden URLs, or malicious character encoding (zero-width characters, homoglyphs) were found in the skill instructions.
- [SAFE]: The skill does not download external scripts, install unverified packages, or execute remote code. It relies on the pre-authenticated Shopify CLI environment provided by the user.
- [SAFE]: Data processing is limited to aggregating return reasons and product SKUs for reporting purposes. While the skill ingests external data (customer return notes), it lacks exploitable capabilities like arbitrary command execution that would make indirect prompt injection a high risk.
Audit Metadata