shopify-admin-fulfillment-status-digest
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill performs legitimate data retrieval from Shopify using official GraphQL queries and tools. Analysis shows the operations are read-only and targeted at order fulfillment data.
- [COMMAND_EXECUTION]: Uses shopify-admin and shopify-admin-execution tools as intended for store management. No malicious or unauthorized command patterns were found.
- [DATA_EXFILTRATION]: No evidence of unauthorized data transmission. Data processing is confined to generating local reports.
- [PROMPT_INJECTION]: While the skill ingests external data from Shopify orders, it poses no risk of indirect prompt injection as it is used for reporting. Ingestion points: GraphQL results in SKILL.md. Boundary markers: None. Capability inventory: shopify-admin-execution tool. Sanitization: None.
Audit Metadata