Third-party audit

Gen Agent Trust Hub

shopify-liquid · shopify/shopify-ai-toolkit

Passed
Provider summary

The skill is developed by Shopify and uses official Shopify resources for theme development tasks. It is generally safe but contains a minor security risk related to indirect prompt injection. The skill instructs the agent to validate generated code by passing it as a string to a shell command, which could be exploited to execute arbitrary commands if the generated code is crafted to break out of shell quoting.

The provider classified the analyzed snapshot as NONE risk. This result applies to the content available at audit time.

Provider
Gen Agent Trust Hub
Normalized result
pass
Risk level
NONE
Audited
May 16, 2026
Interpretation

How to use this signal

01

Confirm the source

Compare the repository, publisher, and installation command before continuing.

02

Read the content

Review SKILL.md, scripts, and allowed tools. Artificial Atlas never executes them during indexing.

03

Limit permissions

Use the narrowest possible scope and avoid broad credentials for third-party skills.