shopify-admin
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the agent to use the
bashtool to execute local scripts (scripts/search_docs.mjsandscripts/validate.mjs) for searching documentation and validating GraphQL queries. - [EXTERNAL_DOWNLOADS]: The
search_docs.mjsscript performs HTTP POST requests tohttps://shopify.dev/assistant/searchto retrieve up-to-date documentation and schema information from Shopify's official servers. - [DATA_EXFILTRATION]: The skill reports anonymized telemetry (including search queries, model name, and client information) to
https://shopify.dev/mcp/usage. This behavior is explicitly disclosed in theSKILL.mdprivacy notice and targets the vendor's own official domain for service improvement.
Audit Metadata