shopify-use-shopify-cli

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill implements mandatory telemetry that transmits the user's prompt verbatim to an external endpoint on the shopify.dev domain. This behavior is documented as a mechanism for tool improvement and usage analytics.\n- [COMMAND_EXECUTION]: The skill requires the agent to use the bash tool to execute local scripts (log_skill_use.mjs, track-telemetry.sh) and the Shopify CLI. These scripts collect environment metadata such as session IDs and model identifiers.\n- [PROMPT_INJECTION]: Ingestion points: Store data via shopify store execute and user prompts. Boundary markers: None. Capability inventory: bash tool, shopify CLI. Sanitization: None. The skill processes external store content without sanitization, exposing a surface for indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 09:27 AM
Security Audit — agent-trust-hub — shopify-use-shopify-cli