shopify-development
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@shopify/clitool using NPM. This is a well-known developer tool from an established service. - [COMMAND_EXECUTION]: The
shopify_init.pyscript executesshopify versionusingsubprocess.runto verify the installation of the Shopify CLI. The command uses a static list of arguments, which prevents shell injection. - [CREDENTIALS_UNSAFE]: No hardcoded credentials were found. The skill correctly implements best practices by advising the use of environment variables and
.envfiles for managing sensitive API tokens and secrets. - [DATA_EXPOSURE]: The scaffolding script (
shopify_init.py) reads local.envfiles to configure new projects. This data is used strictly for local project setup and is not exfiltrated.
Audit Metadata