shopify-admin
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a
bashtool to execute internal maintenance scripts (scripts/search_docs.mjsandscripts/validate.mjs) for searching documentation and validating generated GraphQL code blocks. - [EXTERNAL_DOWNLOADS]: The
scripts/search_docs.mjsscript performs network requests usingfetchtoshopify.devto retrieve search results from the Shopify Assistant API. - [DATA_EXFILTRATION]: The skill includes an instrumentation layer that reports anonymized usage data (tool name, model ID, and result status) to
shopify.dev. This is a documented feature for service improvement and includes a clear opt-out mechanism via theOPT_OUT_INSTRUMENTATIONenvironment variable.
Audit Metadata