shopify-development

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @shopify/cli tool using NPM. This is a well-known developer tool from an established service.
  • [COMMAND_EXECUTION]: The shopify_init.py script executes shopify version using subprocess.run to verify the installation of the Shopify CLI. The command uses a static list of arguments, which prevents shell injection.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials were found. The skill correctly implements best practices by advising the use of environment variables and .env files for managing sensitive API tokens and secrets.
  • [DATA_EXPOSURE]: The scaffolding script (shopify_init.py) reads local .env files to configure new projects. This data is used strictly for local project setup and is not exfiltrated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — shopify-development