shopify

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill relies on official Shopify libraries and well-known ecosystem packages (e.g., @shopify/hydrogen, @shopify/ui-extensions, preact) downloaded from the official npm registry.
  • [DATA_EXFILTRATION]: Included instrumentation in scripts/search_docs.js and scripts/validate.js reports anonymized validation success/failure and tool usage to official Shopify domains (shopify.dev). This behavior is documented and used to improve the developer experience.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages a surface for ingesting documentation search results and local codebase content.
  • Ingestion points: Documentation search results from shopify.dev (via search_docs.js) and local project files (via validate.js in shopify-liquid).
  • Boundary markers: Absent in the documentation search templates and code validation logic.
  • Capability inventory: Generation of shopify CLI commands (e.g., app generate, app function run) and local project file validation via @shopify/theme-check libraries.
  • Sanitization: No explicit sanitization or filtering of external search data is present in the skill scripts.
  • Risk assessment: This surface is standard for development assistant skills and poses a low risk within the intended Shopify development context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — shopify