スキル shopify-automation
📦

shopify-automation

コンテンツリビジョン r1 中リスク ⚙️ 外部コマンド🌐 ネットワークアクセス

Shopifyストア運用を自動化

Shopifyストアのタスクでは、多くの場合、多数のAPIツールと慎重なページネーションが必要です。このスキルは、一般的なストア運用向けのRube MCPワークフローを通じて、Claude、Codex、Claude Codeをガイドします。

対応: Claude Codex Code(CC)
⚠️ 50 不十分

自分のエージェントでインストール

このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。

エージェントリクエスト
Review the Skillstore skill "shopify-automation" from https://skillstore.io/skills/sickn33-shopify-automation.md and its manifest at https://skillstore.io/api/skills/sickn33-shopify-automation/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。

エージェントが読めるリソース

AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。

テストする

「shopify-automation」を使用しています。 先週の未処理Shopify注文を表示してください。

期待される結果:

注文ID、財務ステータス、フルフィルメントステータス、次の確認アクションを含む簡潔な注文サマリー。

「shopify-automation」を使用しています。 これらの在庫アイテムについて、すべてのロケーションの在庫を確認してください。

期待される結果:

低在庫と不足しているロケーションデータを強調した、ロケーション別の在庫レポート。

「shopify-automation」を使用しています。 セール商品用のスマートコレクションを準備してください。

期待される結果:

作成前のルール条件、対象商品、確認手順を含むコレクション計画案。

セキュリティ監査

中リスク

Most static shell-execution findings are false positives caused by Markdown backticks around MCP and Shopify tool names. The real risks are the required third-party Rube MCP OAuth connection and documented Shopify write operations, which need clear consent and permission boundaries.

1
スキャンされたファイル
169
解析済み行数
1
レビュー項目
0
誤検知を無視

確認済みのセキュリティ上の懸念 (2)

中
Third-Party MCP Access to Shopify Data
The skill requires adding Rube MCP and completing Shopify OAuth before store workflows run. That gives a third-party MCP provider access to Shopify products, orders, customers, inventory, and related operations.
The setup instructions explicitly name the Rube MCP endpoint and require a Shopify OAuth connection. The surrounding workflow sections show broad store data access through that connection.
中
Shopify Store Write Operations Need Confirmation
The skill documents bulk product creation, smart collection creation, and adding products to collections. These are legitimate features, but they can materially change a store if run without explicit approval.
The cited lines directly list Shopify write-capable tools. There is no matching instruction that requires a dry run or user confirmation before write actions.
機能レビュー項目 (1)

これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。

低
Hardcoded URL
**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API k
Line 20 instructs users to add the external Rube MCP endpoint. This is expected for the skill, but it creates a real third-party network and OAuth trust boundary.
監査者: codex 監査履歴を表示 →
このレポートを共有・引用

バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。

バージョン別レポートを開く
セキュリティ評価

レポートリンクをコピー

https://skillstore.io/skills/sickn33-shopify-automation/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdownバッジ

[![Skillstore security assessment](https://skillstore.io/badges/skills/sickn33-shopify-automation/security.svg)](https://skillstore.io/skills/sickn33-shopify-automation?utm_source=security_passport_badge)

HTMLバッジ

<a href="https://skillstore.io/skills/sickn33-shopify-automation?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-shopify-automation/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

埋め込みカード

<iframe src="https://skillstore.io/embed/skills/sickn33-shopify-automation.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
学術引用 (APA · BibTeX · CFF)

APA形式の引用

sickn33. (2026). shopify-automation security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-shopify-automation/audits/4

BibTeX形式の引用

@techreport{sickn33-sickn33-shopify-automation-2026, author = {sickn33}, title = {shopify-automation security audit report (audit version 4)}, institution = {Skillstore}, year = {2026}, number = {4}, url = {https://skillstore.io/skills/sickn33-shopify-automation/audits/4}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "shopify-automation security audit report (audit version 4)" version: "unspecified" type: report authors: - name: "sickn33" date-released: "2026-07-07" url: "https://skillstore.io/skills/sickn33-shopify-automation/audits/4" identifiers: - type: other value: "skillstore:sickn33-shopify-automation:audit:4" description: "Skillstore immutable audit report identifier"

Skillstore スコア

このスコアの理由 証拠の信頼度: 高
55
アーキテクチャ
85
保守性
87
コンテンツ
68
コミュニティ
83
仕様準拠

作成できるもの

商品カタログを確認

マーチャンダイジング更新の前に、商品を一覧表示し、個別の商品レコードを確認し、カタログ項目をカウントします。

注文とフルフィルメントを追跡

ステータスで注文をフィルターし、注文詳細を確認し、サポート対応のためにフルフィルメントイベントをレビューします。

ロケーション別に在庫を監視

各ロケーションの在庫レベルを確認し、補充計画のための在庫レポートを準備します。

これらのプロンプトを試す

接続を確認
Rube MCPが利用可能であることを確認し、現在のShopifyツールスキーマを検索して、私のShopify接続が有効かどうかを検証してください。
最近の注文を一覧表示
Rube MCP経由でShopifyツールを使用し、最近の未処理注文を一覧表示してください。支払いステータス、フルフィルメントステータス、注文識別子を含めてください。
在庫レベルを監査
現在のShopifyスキーマを検索し、ストアのロケーションを一覧表示して、関連するロケーション全体でこれらのinventory item IDsの在庫レベルを確認してください。
カタログ更新を計画
現在のツールスキーマを検索し、このベンダーの商品を確認し、コレクション所属を特定し、適用前に商品またはコレクションの変更案を提示してください。

ベストプラクティス

  • Shopifyツールの入力は変更される可能性があるため、各タスクの前にRubeツールスキーマを検索します。
  • データを読み取ったり変更したりする前に、有効なShopify接続と対象ストアを確認します。
  • 商品の一括作成、コレクション変更、GraphQLミューテーションの前に、明示的な承認を求めます。

回避

  • デフォルトの注文フィルターにすべての注文ステータスが含まれると想定しないでください。
  • プレビューとユーザー確認なしに、一括作成やコレクション更新を実行しないでください。
  • 大規模ストアでページネーション、カーソル処理、Shopifyレート制限を無視しないでください。

よくある質問

このスキルにはShopify APIキーが必要ですか?
このスキルはRube MCPとShopify OAuth認可を前提としています。直接的なAPIキー設定は含まれていません。
Shopify商品を作成できますか?
はい、接続済みアカウントに権限がある場合、Shopify toolkitを通じた商品の一括作成をドキュメント化しています。
注文を管理できますか?
Rube MCPを通じて、フィルター付きで注文を一覧表示し、注文詳細を取得し、フルフィルメント情報を確認できます。
在庫ワークフローをサポートしていますか?
はい、ドキュメント化されたShopifyツールを通じて、在庫レベルの確認とロケーション一覧表示をガイドできます。
なぜ最初にツールを検索するのですか?
Rubeツールスキーマは変更される可能性があります。最初に検索することで、エージェントが現在の入力を使用し、古いパラメーターを避けられます。
ユーザーはどの権限を確認すべきですか?
ユーザーは、ワークフローを実行する前に、Shopify OAuthスコープ、ストアID、書き込み権限を確認する必要があります。

開発者情報

作成者

sickn33

ライセンス

MIT

Skillstore リビジョン

r1

バージョンに関する注意

作者はバージョンを宣言していません。

参照

9f814fc6a43fd99946f2da5e0df231c65a38bc76

メンテナンスの新しさ

2026/7/21

利用状況

6 ダウンロード · 89 閲覧

ファイル構成

📄 SKILL.md