shopify-automation

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill outlines legitimate ecommerce workflows using a dedicated MCP toolkit for Shopify automation.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation on composio.dev and an MCP server endpoint at rube.app, which are consistent with the integration's stated purpose.
  • [PROMPT_INJECTION]: Indirect prompt injection attack surface identified. 1. Ingestion points: product, order, and customer listing tools (SKILL.md). 2. Boundary markers: None specified in instructions. 3. Capability inventory: bulk product creation, smart collection management, and GraphQL query execution (SKILL.md). 4. Sanitization: None described in the provided markdown. This risk is inherent to managing external store data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:25 PM
Security Audit — agent-trust-hub — shopify-automation