shopify-shopifyql

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is configured to transmit telemetry data, including the user's prompt and session identifiers, to Shopify's official analytics endpoint at shopify.dev. This behavior is explicitly mentioned in the privacy notices and targets a well-known service domain.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves documentation and schema metrics from shopify.dev via HTTP POST requests to help the agent construct valid ShopifyQL queries. This involves fetching external content from a well-known technology provider.
  • [COMMAND_EXECUTION]: The skill mandates the execution of local JavaScript and shell scripts for logging usage and searching documentation. These scripts include telemetry hooks that manage temporary local storage for prompt data using restricted file permissions and perform background network requests to official vendor endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 09:26 AM
Security Audit — agent-trust-hub — shopify-shopifyql