Agent skill

Commerce App Review

by adobe in adobe/skills

A skill your agent uses when validating an App Builder app before submitting to Adobe Exchange, or when the user mentions Adobe Commerce app compliance, extension review, marketplace submission, or…

Apache-2.0Auto-check passedSales & Support

Install Commerce App Review

skills CLI
$ npx skills add adobe/skills --skill commerce-app-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install adobe/skills commerce-app-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/commerce/app-review/skills/commerce-app-review .claude/skills/commerce-app-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
commerce-app-review
GitHub stars
196
Token cost
~2.2k tokens
SKILL.md length
1,050 words
Files
48 (incl. references)
Skills in repo
65
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when validating an App Builder app before submitting to Adobe Exchange, or when the user mentions Adobe Commerce app compliance, extension review, marketplace submission, or…

  • Works in 8 steps: Validate the path and app type → Load local references → Fetch the guidelines → …
  • Validating an App Builder app before submitting to Adobe Exchange
  • SKILL.md covers Inputs, Procedure, Obtain IMS token and Enrich a finding, plus 1 more section
  • Runs JavaScript scripts from its folder; calls curl, npm and npx; reaches raw.githubusercontent.com and commerce-docs-prod-endpoint-d0ctgyebe7bec8e6.a02.azurefd.net; needs IMS_TOKEN

What it does

Commerce App Review is an agent skill from adobe/skills. Use when validating an App Builder app before submitting to Adobe Exchange, or when the user mentions Adobe Commerce app compliance, extension review, marketplace submission, or Adobe Exchange listing. Checks security requirements, project structure, documentation completeness, and dependency health; reports MUST-have blockers and NICE-to-have recommendations and walks through each finding interactively.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 56 other files, including reference files (for example `evals/evals.json`, `evals/files/deployment-issues-app/actions/sync/index.js` and `evals/files/deployment-issues-app/app.config.yaml`).

It sits in Sales & Support, covering Customer feedback analysis. It works with Adobe Commerce. The repository describes itself as: Adobe Skills for Agents. The licence is Apache-2.0.

When your agent uses it

  • Validating an App Builder app before submitting to Adobe Exchange
  • The user mentions Adobe Commerce app compliance
  • Extension review
  • Marketplace submission

Example prompts

  • “/commerce-app-review”

Requirements

  • Node.js
  • A credential in IMS_TOKEN

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Validate the path and app type
  2. Load local references
  3. Fetch the guidelines
  4. Read the app
  5. Review
  6. Present the raw findings list
  7. Respond to the user
  8. Walkthrough mode

What it can do on your machine

Read from SKILL.md and the folder at commit 985c436. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • curl
    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • raw.githubusercontent.com
    • commerce-docs-prod-endpoint-d0ctgyebe7bec8e6.a02.azurefd.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • IMS_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Commerce App Review loads about 2.2k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 1,050 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from adobe/skills at commit 985c436, republished under its Apache-2.0 licence (© adobe). 1,050 words, ~2,229 tokens.

Download SKILL.mdSave it as .claude/skills/commerce-app-review/SKILL.md (or your agent's skills folder). This skill also uses 47 other files; get the full folder from GitHub.
name
commerce-app-review
description
Use when validating an App Builder app before submitting to Adobe Exchange, or when the user mentions Adobe Commerce app compliance, extension review, marketplace submission, or Adobe Exchange listing. Checks security requirements, project structure, documentation completeness, and dependency health; reports MUST-have blockers and NICE-to-have recommendations and walks through each finding interactively.
license
Apache-2.0

Self-review an App Builder app

Reviews a local app directory against Adobe's Commerce submission guidelines and walks through each finding interactively — MUST-have blockers first, then NICE-to-have recommendations.

Inputs

  • APP_PATH (optional) — path to the app root. Defaults to the current working directory.
  • APP_TYPE (required) — downloadable or non-downloadable. A downloadable app allows merchants to download the source package; a non-downloadable app is installed directly from Adobe Exchange with one click.

Procedure

1. Validate the path and app type

If APP_PATH is not provided, use the current working directory. Confirm it exists and is a directory. If not, stop and report:

Path not found. Please provide the path to the root of your app codebase.

If APP_TYPE is not provided, ask:

Is this app downloadable or non-downloadable?

  • Downloadable — merchants download the source package and deploy it themselves
  • Non-downloadable — merchants install directly from Adobe Exchange with one click

Do not proceed until both are confirmed.

Check whether aio is installed (e.g. command -v aio). This is a presence check only — do not attempt to authenticate at this stage. If aio is not found, note it once:

Note: aio isn't installed. Walkthrough enrichment (Step 8) will use fallback knowledge unless aio is installed and authenticated before then.

Continue either way.

2. Load local references

Read references/finding.md and all files under references/exceptions/ (paths relative to this skill file).

Load pattern files conditionally:

  • references/patterns/cors-storefront-actions.md — always
  • references/patterns/accs-rest-api-dependency.md — always
  • references/patterns/aio-commerce-sdk.md — always
  • references/patterns/admin-ui-sdk.md — only if commerce/backend-ui/1 is in app.config.yaml or ext.config.yaml, or @adobe/uix-guest/@adobe/uix-core in package.json

Pattern files take precedence over fetched guidelines. Exception files suppress findings from both.

If any file is not found, skip and continue.

3. Fetch the guidelines

Fetch both pages using curl. Use raw GitHub URLs — the rendered developer.adobe.com pages are not reliably accessible:

  • Submission guidelines: https://raw.githubusercontent.com/AdobeDocs/commerce-extensibility/refs/heads/main/src/pages/app-development/app-submission-guidelines.md
  • Admin UI SDK checklist: https://raw.githubusercontent.com/AdobeDocs/commerce-extensibility/refs/heads/main/src/pages/admin-ui-sdk/app-review-checklist.md — only if commerce/backend-ui/1 is in app.config.yaml or ext.config.yaml, or @adobe/uix-guest/@adobe/uix-core in package.json

If a page is unreachable, note which one failed, proceed with the other, and warn the user that coverage is partial.

4. Read the app

Read these files in order:

  1. app.config.yaml — extension points, actions, inputs, annotations, productDependencies
  2. package.json — name, description, author, version, dependencies, scripts
  3. env.dist / env.example / any env.* at the root — documented env vars
  4. README.md — installation instructions, events, API requirements
  5. deploy.yaml — app ID, APIs, workspaces
  6. install.yaml — extension points (if Admin UI SDK detected)
  7. Every *.config.yaml and ext.config.yaml under src/ and actions/
  8. Every index.js under actions/
  9. web-src/src/ — UI code, innerHTML, routing
  10. extension-manifest.json — if Admin UI SDK detected

If a file does not exist, note it and continue.

5. Review

Build a complete list of checks from the pattern files and fetched guidelines. Then work through every item silently, one by one. Do not skip any item.

Exclude the following entirely — do not check:

  • npm audit, npx npm-check, or any check requiring running npm
  • Exchange listing URL, repository visibility, screenshots in Exchange listing
  • Any check requiring a live Exchange listing, deployed environment, or external URL

For each item:

  • Check it against the files read in Step 4
  • If confirmed → record as FINDING with severity, file, and line number
  • If an exception in references/exceptions/ applies → suppress it
  • If not applicable to APP_TYPE → skip it

Before recording any FINDING, verify it in the actual files. If you cannot point to a specific file and line number, do not flag it.

Before flagging a missing package — verify it is directly imported in source files, not just a transitive dependency.

After working through all items, collect all FINDINGs and assign codes: MUST-<n> and NICE-<n>. Merge closely related findings before assigning codes.

For each finding track:

  • SEVERITY — MUST or NICE
  • DESCRIPTION — one sentence, specific and actionable
  • FILE_PATH — absolute path to the relevant file; empty for general issues. Render as a markdown link: [relative/path](file:///absolute/path)
  • LINE_NUMBER — specific line; 0 for general issues
  • CATEGORY — one or more of: security · documentation · code · dependencies · other
Show full SKILL.md (409 more words)Show less
6. Present the raw findings list

Print a concise findings list — no enrichment yet. Format:

Found N MUST-have issue(s) and M NICE-to-have recommendation(s).

**MUST — blockers**
- MUST-1: <one-line description> (`<FILE_PATH>`, line <LINE_NUMBER>)
- MUST-2: …

**NICE — recommendations**
- NICE-1: <one-line description> (`<FILE_PATH>`, line <LINE_NUMBER>)
- NICE-2: …

Omit a group heading if it is empty. Omit the file reference when FILE_PATH is empty.

After the list, show:

Type walkthrough to go through each finding · MUST-n or NICE-n to dig into a specific one · or ask anything.

Then wait for the user's response.

7. Respond to the user
  • "walkthrough" (or equivalent intent) → go to Step 8
  • A finding code (e.g. "MUST-2", "NICE-1") → enrich that finding and present it; show the actions line again and wait
  • Anything else → answer it; show the actions line again and wait

Repeat until the user ends the session or all findings have been walked through.

8. Walkthrough mode

Work through all findings sequentially — MUST first, then NICE. Before starting, obtain the IMS token (see below).

  • If the group is empty, say so and move on.
  • For each finding in code order:
    1. Show a numbered header (e.g. --- MUST issue [n/N] ---)
    2. Enrich the finding and print it
    3. Show: **"resolve it"** to work on this finding together · **"next"** to move on · or ask anything
    4. Wait for the user's reply

After the last finding, close with a short encouraging message including how many findings were resolved (e.g. "X of N+M findings resolved") and wish the developer good luck.


Obtain IMS token

Run once per session, the first time enrichment is needed:

bash
IMS_TOKEN=$(aio auth login --bare 2>/dev/null)
  • If $IMS_TOKEN is non-empty → use the documentation agent for enrichment.
  • If empty → warn the user; instruct them to run aio login and restart for the best experience; ask whether to continue without enrichment or stop.

Enrich a finding

  1. If IMS token is available, query the documentation agent:
bash
curl -s -X POST https://commerce-docs-prod-endpoint-d0ctgyebe7bec8e6.a02.azurefd.net/api/query \
  -H "Authorization: Bearer $IMS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"query": "<topic derived from the finding>", "count": 5}'

Pick the index based on category:

  • security, deployment, code → app-builder-docs
  • documentation, dependencies → commerce-extensibility-docs
  • default → omit index
  1. Read the actual file at FILE_PATH and LINE_NUMBER. Generate a concrete before/after fix specific to the developer's code — not a generic example.

  2. Compose the enriched finding using the format in references/finding.md.

If the agent returns no results, fall back to App Builder / Commerce knowledge and continue.

Failure modes

  • Path not found → stop and report; do not proceed
  • Guidelines page unreachable → note which failed; proceed with the other; warn coverage is partial
  • aio not installed or not authenticated → warn the user, instruct them to run aio login, and ask whether to continue without enrichment or stop
  • Documentation agent returns no results → fall back to App Builder / Commerce knowledge; do not stop

© adobe, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 47 other files (references) in plugins/commerce/app-review/skills/commerce-app-review of adobe/skills.

  • SKILL.md
  • evals/evals.json
  • evals/files/deployment-issues-app/actions/sync/index.js
  • evals/files/deployment-issues-app/app.config.yaml
  • evals/files/deployment-issues-app/package.json
  • evals/files/security-issues-app/README.md
  • evals/files/security-issues-app/actions/get-catalog/index.js
  • evals/files/security-issues-app/actions/update-product/index.js
  • evals/files/security-issues-app/app.config.yaml
  • evals/files/security-issues-app/env.dist
  • evals/files/security-issues-app/package.json
  • evals/files/well-formed-app
  • … and 36 more

Open the folder on GitHubat commit 985c436

Compare with similar skills

Commerce App Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Commerce App Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Commerce App Review this skilladobe/skills196—~2.2kAutomated safety check: PassApache-2.0
Zsxqunnoo/zsxq-skill304—~3.8kAutomated safety check: PassMIT
Creating SurveysPostHog/posthog40k—~1.6kAutomated safety check: PassCustom licence
Pp Trustpilotmvanhorn/printing-press-library2.1k—~3.7kAutomated safety check: NotesApache-2.0
Sealeap Fenghuang Amazon Product Exclusion Review Miningxjli360/sealeap-amazon-skills240—~711Automated safety check: PassMIT
Review Analysisliangdabiao/amazon-sorftime-research-MCP-skill9461 repos~2.5kAutomated safety check: PassNone

Similar skills

  • Zsxq

    unnoo/zsxq-skill

    知识星球 CLI(zsxq-cli)与底层接口完整操作指南,涵盖星球和内容管理、Skill Pay 微信支付场景。当用户提到知识星球、zsxq、小密圈、星球、登录/认证、发帖、评论、回答、编辑、删除主题、定时发布/定时任务/定时回答、投票、问答主题、markdown 正文、AI…

    304 GitHub stars~3.8k tokensUpdated 17 days ago
    Sales & SupportAuto-check passed
  • Creating Surveys

    PostHog/posthog

    Official

    Creates and launches PostHog surveys through MCP, including NPS/CSAT popovers, hosted feedback forms, and headless surveys.

    40k GitHub stars~1.6k tokensUpdated today
    Sales & SupportAuto-check passed
  • Pp Trustpilot

    mvanhorn/printing-press-library

    Every Trustpilot review surface, plus the local SQLite database and balanced good-and-bad agent bundle no other...

    2.1k GitHub stars~3.7k tokensUpdated yesterday
    Sales & SupportAuto-check: notes
  • Screen product ideas for the US marketplace with an exclusion list—too cheap, trend-driven, seasonal, restricted—then mine competitor listings and low-star reviews for fixable defects, and confirm…

    240 GitHub stars~711 tokensUpdated 10 days ago
    Sales & SupportAuto-check passed
  • Review Analysis

    liangdabiao/amazon-sorftime-research-MCP-skill

    对亚马逊商品评论进行深度分析,自动识别产品痛点、分析退货原因,生成改进建议和客服回复模板。Invoke when user uses /review-analysis command with a product ASIN.

    946 GitHub starsUsed in 1 repo~2.5k tokens
    Sales & SupportAuto-check passed
  • Bggg Data Amazon

    binggandata/bggg-skills

    Collect Amazon.com written product reviews at scale through Woot's public review AJAX route, retain every attempt and error log, reconcile partial runs, and normalize exact review text into…

    603 GitHub stars~1.4k tokensUpdated 1 mo ago
    Sales & SupportAuto-check passed

More from adobe/skills

All 65 skills in this repo
  • Scaffolds, implements, deploys and debugs Adobe Runtime actions in App Builder projects, with templates for webhooks, events, database CRUD, sequences and Asset Compute workers.

    196 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Launches Chrome with an unpacked extension over CDP, opens its sidepanel, popup or options page, and hands over to cdp-connect for clicks, typing and screenshots.

    196 GitHub stars~952 tokensUpdated yesterday
    Auto-check passed
  • Extracts icons, metadata, text, forms, videos and social links from any web page with playwright-cli, with SVG icon classification and cleanup.

    196 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Page Langs

    adobe/skills

    Detect all languages used on a webpage — both declared (html@lang, hreflang alternate links, nested lang= attributes, meta content-language) and actually present in the body text (Google CLD3 via…

    196 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Page Prep

    adobe/skills

    Prepare any webpage for clean interaction by detecting and removing disruptive overlays (cookie banners, GDPR consent, modals, popups, newsletter signups, paywalls, login walls).

    196 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Page Reduce

    adobe/skills

    Reduce a webpage to a structural skeleton with semantic tokens.

    196 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Commerce App Review

What does Commerce App Review do?

A skill your agent uses when validating an App Builder app before submitting to Adobe Exchange, or when the user mentions Adobe Commerce app compliance, extension review, marketplace submission, or…. Commerce App Review is an agent skill from adobe/skills. Use when validating an App Builder app before submitting to Adobe Exchange, or when the user mentions Adobe Commerce app compliance, extension review, marketplace submission, or Adobe Exchange listing.

When should I use Commerce App Review?

Commerce App Review fits situations like: validating an App Builder app before submitting to Adobe Exchange; the user mentions Adobe Commerce app compliance; extension review; marketplace submission.

How do I install Commerce App Review in Claude Code?

Run `npx skills add adobe/skills --skill commerce-app-review -a claude-code`. Or copy the skill folder (plugins/commerce/app-review/skills/commerce-app-review in adobe/skills) into .claude/skills/commerce-app-review in your project. Claude Code loads it when a task matches its description.

How do I install Commerce App Review in Codex?

Run `npx skills add adobe/skills --skill commerce-app-review -a codex`. Or copy the skill folder (plugins/commerce/app-review/skills/commerce-app-review in adobe/skills) into .agents/skills/commerce-app-review in your project. Codex loads it when a task matches its description.

Can I use Commerce App Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add adobe/skills --skill commerce-app-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/commerce-app-review, .gemini/skills/commerce-app-review, .github/skills/commerce-app-review and .opencode/skills/commerce-app-review in your project.

What does Commerce App Review need to run?

Going by SKILL.md and its folder, Commerce App Review needs JavaScript for the scripts in its folder, the command-line tools its instructions call (curl, npm and npx) and credentials named IMS_TOKEN. Our summary lists: Node.js; A credential in IMS_TOKEN.

Does Commerce App Review access the network?

SKILL.md names 2 domains. In commands or code: raw.githubusercontent.com and commerce-docs-prod-endpoint-d0ctgyebe7bec8e6.a02.azurefd.net; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Commerce App Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Commerce App Review use?

Commerce App Review is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Commerce App Review use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Commerce App Review?

Skills that share tags, products or a category with Commerce App Review: Zsxq (unnoo/zsxq-skill, 304 stars), Creating Surveys (PostHog/posthog, 40k stars), Pp Trustpilot (mvanhorn/printing-press-library, 2.1k stars) and Sealeap Fenghuang Amazon Product Exclusion Review Mining (xjli360/sealeap-amazon-skills, 240 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Commerce App Review?

adobe (a GitHub organization) maintains it in adobe/skills, which has 196 GitHub stars. The repository holds 65 skills in this directory. The repository was last updated on October 7, 2026.

Source: adobe/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.