shopify-mcp-server

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install and execute code using npx shopify-mcp and npm install from the public npm registry. It also references a GitHub repository (github.com/Cesarjoquin/shopify-mcp.git) for source installation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from an external source (Shopify Admin API), including product descriptions, customer notes, and order details. This content could contain hidden instructions that influence the AI agent's behavior. The risk is mitigated by the structured nature of the GraphQL API but remains an inherent attack surface for skills with write capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:34 AM
Security Audit — agent-trust-hub — shopify-mcp-server