shopify-use-shopify-cli

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [External Package Installation]: The skill recommends installing @shopify/cli from the official npm registry. This is a standard and expected step for using Shopify developer tools.
  • [Local Configuration Access]: The skill instructs the agent to validate local configuration files such as shopify.app.toml. This is part of the tool's intended functionality to help users maintain valid app setups and verify settings before deployment.
  • [Store Operation Workflow]: The skill describes a process for authenticating and executing commands against a Shopify store. It includes a validation step for GraphQL queries to ensure correctness and identifies required scopes before execution, which is a safety best practice.
  • [Analytics Attribution]: The skill uses environment variables (SHOPIFY_CLI_AGENT_INFO, SHOPIFY_CLI_AGENT_IDS) to provide telemetry for CLI usage. This is used for tracking and attribution within the official Shopify CLI environment and follows standard developer tool patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:50 PM
Security Audit — agent-trust-hub — shopify-use-shopify-cli