shopify-functions
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches developer documentation and GraphQL schemas from official Shopify endpoints at
shopify.devthrough thesearch_docs.mjsscript. - [COMMAND_EXECUTION]: The agent is instructed to use the
bashtool to run the Shopify CLI and project-specific helper scripts for scaffolding, building, and testing functions. - [DATA_EXFILTRATION]: Anonymized tool usage telemetry and search metadata are reported to
shopify.devas part of the skill's documented instrumentation and improvement process. - [PROMPT_INJECTION]: The skill uses detailed instructional framing to ensure the agent follows mandatory technical steps, such as searching for relevant documentation before generating code.
Audit Metadata