shopify-development

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/shopify_init.py executes shopify version using subprocess.run to check if the Shopify CLI is installed. The command is hardcoded and does not involve shell interpolation of user-provided data.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and requirements file refer to the official Shopify CLI and development tools available through NPM (@shopify/cli, @shopify/theme). These are well-known resources provided by Shopify for developers.
  • [DATA_EXFILTRATION]: The EnvLoader class in scripts/shopify_init.py searches for .env files in the current and parent directories to load Shopify API credentials. This is a common pattern for local development tools to facilitate configuration without hardcoding secrets.
  • [CREDENTIALS_UNSAFE]: The skill provides guidance on managing Shopify API keys and secrets. It correctly advises storing these sensitive values in environment variables rather than source code, and includes logic to load them from .env files or the system environment. No hardcoded credentials were found.
  • [PROMPT_INJECTION]: The shopify_init.py script presents a potential indirect prompt injection surface as it ingests user input via input() to define project names and paths, which are then used for directory creation and file writes.
  • Ingestion points: input() function in scripts/shopify_init.py is used to collect project names and access scopes.
  • Boundary markers: None present; the script assumes the input is provided by a trusted source.
  • Capability inventory: subprocess.run (for version checks), Path.mkdir, and Path.write_text are used for project scaffolding in scripts/shopify_init.py.
  • Sanitization: There is no explicit sanitization of project names before they are used in path construction (e.g., Path.cwd() / app_name), though the use of Python's Path library provides standard structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:20 PM
Security Audit — agent-trust-hub — shopify-development