shopify-content
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill facilitates interaction with the Shopify GraphQL and REST Admin APIs for legitimate store management tasks. It correctly uses placeholders like
{token}and{store}for sensitive credentials and store-specific domains, which prevents the hardcoding of secrets and ensures user-controlled parameters are used. - [SAFE]: All shell commands using
curlare limited to standard API requests to Shopify's infrastructure. There is no evidence of remote script execution, unauthorized file access, or data exfiltration to third-party domains. - [SAFE]: The skill uses browser automation for navigation tasks as a fallback for limited API support, which is a documented and expected workflow for the platform.
Audit Metadata