shopify-development

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/shopify_init.py executes shopify version using subprocess.run to verify that the required development tools are installed.
  • Evidence: subprocess.run(['shopify', 'version'], ...) in scripts/shopify_init.py is used for a benign environment check.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and setup instructions reference official Shopify development tools.
  • Evidence: Mentions of npm install -g @shopify/cli@latest in README.md and SKILL.md target well-known, official packages from the Shopify organization.
  • [CREDENTIALS_UNSAFE]: The initialization script contains logic to read Shopify API keys and secrets from local environment files.
  • Evidence: The EnvLoader class in scripts/shopify_init.py scans for .env files in standard AI agent directories (e.g., .agent, .claude). The script uses these values locally to populate project configuration files like shopify.app.toml and does not exfiltrate the data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — shopify-development