shopify-admin-vendor-consolidation
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates in a read-only manner, querying product information (titles and vendors) via Shopify's GraphQL API without executing any mutations or data modifications.
- [SAFE]: No external network connections, remote code execution, or suspicious dependencies were identified; all data processing occurs within the agent's local context.
- [SAFE]: The skill includes instructions for data normalization (trimming, space collapsing, and suffix removal) which helps mitigate potential issues with malformed input strings.
- [SAFE]: Indirect prompt injection risk is minimal as the skill lacks dangerous execution capabilities (such as shell access) and the ingested product data is used for string clustering and reporting purposes only.
Audit Metadata