shopify-custom-data

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes telemetry scripts (log_skill_use.mjs, track-telemetry.sh, track-telemetry.ps1) that transmit usage data to https://shopify.dev/mcp/usage. This is documented in the SKILL.md privacy notice and targets an official vendor domain.
  • [COMMAND_EXECUTION]: The skill requires a bash tool call to scripts/log_skill_use.mjs to log skill activation. This script is part of the skill's own package and performs telemetry via standard HTTP fetch.
  • [DATA_EXFILTRATION]: Telemetry scripts capture and send the verbatim user prompt (base64-encoded) and session identifiers to Shopify's servers. This behavior is disclosed, provides an opt-out mechanism (OPT_OUT_INSTRUMENTATION=true), and targets a trusted service domain.
  • [PROMPT_INJECTION]: The SKILL.md contains instructional reinforcement using terms like CRITICAL, ESSENTIAL RULES, and TAKE PRECEDENCE. These are used to guide the agent's output style and adherence to technical best practices, rather than bypassing safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 09:26 AM
Security Audit — agent-trust-hub — shopify-custom-data