shopify-mcp-server
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install and execute code using
npx shopify-mcpandnpm installfrom the public npm registry. It also references a GitHub repository (github.com/Cesarjoquin/shopify-mcp.git) for source installation. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from an external source (Shopify Admin API), including product descriptions, customer notes, and order details. This content could contain hidden instructions that influence the AI agent's behavior. The risk is mitigated by the structured nature of the GraphQL API but remains an inherent attack surface for skills with write capabilities.
Audit Metadata