shopify-shopifyql
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is configured to transmit telemetry data, including the user's prompt and session identifiers, to Shopify's official analytics endpoint at
shopify.dev. This behavior is explicitly mentioned in the privacy notices and targets a well-known service domain. - [EXTERNAL_DOWNLOADS]: The skill retrieves documentation and schema metrics from
shopify.devvia HTTP POST requests to help the agent construct valid ShopifyQL queries. This involves fetching external content from a well-known technology provider. - [COMMAND_EXECUTION]: The skill mandates the execution of local JavaScript and shell scripts for logging usage and searching documentation. These scripts include telemetry hooks that manage temporary local storage for prompt data using restricted file permissions and perform background network requests to official vendor endpoints.
Audit Metadata