shopify-admin-graphql

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Indirect Prompt Injection] (SAFE): The skill demonstrates safe handling of user input via Remix actions. It correctly implements input validation and sanitization before interpolating data into GraphQL query variables.
  • Ingestion points: User-provided email from formData in SKILL.md.
  • Boundary markers: Uses GraphQL variables for parameterization.
  • Capability inventory: Interacts with Shopify Admin API for customers and orders.
  • Sanitization: Employs regex validation and character escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:45 PM