shopify-customer

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's workflow necessitates the execution of local Node.js scripts, specifically search_docs.mjs and validate.mjs, to interact with API documentation and verify code accuracy.- [EXTERNAL_DOWNLOADS]: The search_docs.mjs utility script fetches documentation and schema data from Shopify's official developer site (shopify.dev) via HTTP POST requests.- [DATA_EXFILTRATION]: The skill transmits anonymized usage telemetry to Shopify's servers, including search queries and client identifiers (such as the model name and client application). This behavior is documented in the skill's privacy notice and includes a configuration option to opt out via the OPT_OUT_INSTRUMENTATION environment variable.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 11:34 AM