shopify-development
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/shopify_init.pyscript executes a version check usingsubprocess.run(['shopify', 'version']). This call is restricted to a static command list and does not use a shell, preventing command injection.\n- [EXTERNAL_DOWNLOADS]: The documentation and setup scripts reference the installation of the official Shopify CLI via NPM. Shopify is a well-known and trusted service provider, and these downloads are standard for the intended development workflow.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the development of apps that ingest data from Shopify webhooks and API endpoints (e.g., product titles, order details). While this introduces an ingestion surface for untrusted data, the skill includes explicit best practices for mitigation:\n - Ingestion points: Data is received via GraphQL queries in
shopify_graphql.pyand webhook handlers inreferences/app-development.md.\n - Boundary markers: None explicitly defined for agent context, but instructions advise developer-level validation.\n
- Capability inventory: The skill provides file-writing capabilities in
shopify_init.pyfor project setup and network operations inshopify_graphql.pyfor API interaction.\n - Sanitization: The
references/extensions.mdguide specifically mandates sanitizing user input and verifying HMAC signatures to maintain data integrity.
Audit Metadata