shopify-automation
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from a Shopify store (e.g., product details, order information, and customer lists) through tools like SHOPIFY_GET_PRODUCTS and SHOPIFY_GET_ORDERS. This content is processed by the agent and could potentially contain malicious instructions intended to influence subsequent actions. * Ingestion points: Tools such as SHOPIFY_GET_PRODUCTS, SHOPIFY_GET_ORDER, and SHOPIFY_GET_ALL_CUSTOMERS in SKILL.md. * Boundary markers: None identified in the provided instructions. * Capability inventory: The skill provides capabilities to write/modify store data using tools like SHOPIFY_BULK_CREATE_PRODUCTS and SHOPIFY_ADD_PRODUCT_TO_COLLECTION. * Sanitization: No specific sanitization or validation steps are outlined for the ingested data.
- [EXTERNAL_DOWNLOADS]: The setup instructions require adding a remote MCP server endpoint (https://rube.app/mcp). While this is necessary for the skill's stated purpose, it involves connecting the agent to an external infrastructure.
Audit Metadata