Claude security directory

Shopify

Published by Shopify

High risk

Build, manage, and analyze your Shopify store

Security assessment

Plutonium assessed this interactive connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.

Available capabilities

This add-on exposes 25 tools or capabilities.

  • search_products
  • get-shop-info
  • get-product
  • create-product
  • update-product
  • list-orders
  • get-order
  • list-customers
  • get-inventory-levels
  • set-inventory
  • create-discount
  • add-to-collection
  • run-analytics-query
  • bulk-update-product-status
  • search_collections
  • get-collection
  • create-collection
  • update-collection
  • upload-image
  • switch-shop
  • graphql_schema
  • graphql_query
  • graphql_mutation
  • validate_graphql_codeblocks

The interactive security report will load automatically.