skills/ericrisco/rsc-harness/shopify/Gen Agent Trust Hub

shopify

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill actively promotes security best practices, such as instructing the agent to use Liquid filters like | escape, | money, and | json to prevent cross-site scripting (XSS) and ensuring that sensitive API credentials are kept in environment variables rather than committed to configuration files.
  • [COMMAND_EXECUTION]: Includes a utility script scripts/verify.sh designed to perform advisory quality scans. This script uses standard Unix tools (find, grep, sed) to search for deprecated Shopify patterns in the local directory. It is diagnostic in nature and does not perform network operations or access sensitive system files like SSH keys or environment configs.
  • [EXTERNAL_DOWNLOADS]: The skill references official Shopify development tools, such as the Shopify CLI (4.x) and reputable library packages under the @shopify scope on NPM. These are established, well-known resources provided by a trusted technology vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — shopify