shopify-development
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/shopify_init.pyexecutesshopify versionusingsubprocess.runto verify that the required development tools are installed. - Evidence:
subprocess.run(['shopify', 'version'], ...)inscripts/shopify_init.pyis used for a benign environment check. - [EXTERNAL_DOWNLOADS]: The skill documentation and setup instructions reference official Shopify development tools.
- Evidence: Mentions of
npm install -g @shopify/cli@latestinREADME.mdandSKILL.mdtarget well-known, official packages from the Shopify organization. - [CREDENTIALS_UNSAFE]: The initialization script contains logic to read Shopify API keys and secrets from local environment files.
- Evidence: The
EnvLoaderclass inscripts/shopify_init.pyscans for.envfiles in standard AI agent directories (e.g.,.agent,.claude). The script uses these values locally to populate project configuration files likeshopify.app.tomland does not exfiltrate the data.
Audit Metadata