Clawpify
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The OpenClaw AgentSkills skill bundle for Shopify GraphQL API is classified as benign. While it provides extensive capabilities to manage a Shopify store, including sensitive operations like creating/deleting products, adjusting inventory, processing refunds, and managing discounts, the `SKILL.md` and numerous `references/*.md` files consistently and explicitly instruct the AI agent to seek explicit user permission before executing any 'dangerous' or 'permanent' operations. This proactive instruction to the agent to involve the user for high-impact actions is a strong security feature, not a vulnerability, and there is no evidence of malicious execution, data exfiltration, persistence, or obfuscation.
