shopify-app-store-ads
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists exclusively of instructional documentation and configuration files with no executable code, significantly limiting the technical attack surface.
- [EXTERNAL_DOWNLOADS]: The skill references official documentation from Shopify's help center, which is a well-known and trusted service for this domain.
- [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection by ingesting untrusted data from external community platforms.
- Ingestion points: The keyword research and campaign brief sections utilize data from Reddit and app reviews (SKILL.md).
- Boundary markers: The instructions require the agent to clearly label community sources as anecdotal and maintain a strict separation between evidence and hypotheses.
- Capability inventory: The skill guides the agent in configuring ads, keywords, and budgets within the Shopify Partner Dashboard.
- Sanitization: The skill mandates verification against official Shopify documentation and requires explicit, restated user approval before any financial commitment is made.
Audit Metadata