Official agent skill

Commerce Trust Safety

by anthropics in anthropics/commerce-agents

The rules the reference agents enforce in code for third-party content, writes, grounding, identity, and memory, each with its module, plus two adversarial-eval rules.

OfficialApache-2.0Auto-check passed

Install Commerce Trust Safety

skills CLI
$ npx skills add anthropics/commerce-agents --skill commerce-trust-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install anthropics/commerce-agents commerce-trust-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/anthropics/commerce-agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/commerce-builder/skills/commerce-trust-safety .claude/skills/commerce-trust-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
commerce-trust-safety
GitHub stars
3.2k
Token cost
~1.8k tokens
SKILL.md length
897 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

The rules the reference agents enforce in code for third-party content, writes, grounding, identity, and memory, each with its module, plus two adversarial-eval rules.

  • Works in 4 steps: Every tool result from catalog, review,… → The label and the notice are per-role… → The per-request block (profile, cart,… → …
  • SKILL.md covers Fence third-party content, Gate writes on provenance and…, Ground the answers that are… and Hold identity on the server, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Commerce Trust Safety is an agent skill from anthropics/commerce-agents, published by the product's own GitHub organization. The rules the reference agents enforce in code for third-party content, writes, grounding, identity, and memory, each with its module, plus two adversarial-eval rules. Load when handling untrusted tool results, guarding a write tool, or scoping what an agent remembers.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Reference blueprint for building shopping and merchant agents with Claude. Examples in retail, commerce, telecom, and entertainment included. The licence is Apache-2.0.

Example prompts

  • “/commerce-trust-safety”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Every tool result from catalog, review, policy, order, metric, message, or web content goes through
  2. The label and the notice are per-role constants (STOREFRONT_FENCE in shopping_agent/fencing.py, MERCHANT_FENCE in
  3. The per-request block (profile, cart, memory facts, page, store context) sits inside the same fence after the cache
  4. A model-supplied result count is clamped to max_search_results (clamp_limit in commerce_common/execution.py).

What it can do on your machine

Read from SKILL.md and the folder at commit fd4d592. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Commerce Trust Safety loads about 1.8k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 897 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from anthropics/commerce-agents at commit fd4d592, republished under its Apache-2.0 licence (© anthropics). 897 words, ~1,836 tokens.

Download SKILL.mdSave it as .claude/skills/commerce-trust-safety/SKILL.md (or your agent's skills folder).
name
commerce-trust-safety
description
The rules the reference agents enforce in code for third-party content, writes, grounding, identity, and memory, each with its module, plus two adversarial-eval rules. Load when handling untrusted tool results, guarding a write tool, or scoping what an agent remembers.

Trust and safety rules

commerce_common/ is commerce-common/commerce_common/, shopping_agent/ is shopping-agent/core/shopping_agent/, and merchant_agent/ is merchant-agent/core/merchant_agent/; docs/safety.md lists the same rules. A rule inside a tool call holds on all three paths, which share one executor (commerce-architecture); rules 10 and 15 name the paths they run on. Merchant staging, guardrails, approval, and marketplace posture are in commerce-merchant-operations.

Fence third-party content

  1. Every tool result from catalog, review, policy, order, metric, message, or web content goes through Fence.fence_payload (commerce_common/fencing.py): NFKC-normalized, invisible and control characters removed, fence markers, forged turn markers, and special tokens replaced, wrapped in the role's label, and cut at max_fenced_chars. The executor's _fenced applies it to every handler.
  2. The label and the notice are per-role constants (STOREFRONT_FENCE in shopping_agent/fencing.py, MERCHANT_FENCE in merchant_agent/fencing.py); the notice appears once, in the static prompt, with nothing untrusted in it.
  3. The per-request block (profile, cart, memory facts, page, store context) sits inside the same fence after the cache breakpoint (build_dynamic_context in each role's prompt.py); backend context blocks have their own cap.
  4. A model-supplied result count is clamped to max_search_results (clamp_limit in commerce_common/execution.py).

Gate writes on provenance and caps

  1. A cart write accepts only ids in ShoppingSessionState.seen_products, filled by the session's catalog and order reads (check_provenance and remember_order_items in shopping_agent/gates.py); update and remove also accept a line already in the cart. Merchant staging accepts only ids in seen_listings and read_listings, apply and discard only ids in seen_changes (merchant_agent/gates.py; commerce-merchant-operations).
  2. max_quantity_per_item caps the line after the write and max_cart_lines the cart, under a session lock (gated_add_to_cart in shopping_agent/gates.py; caps in shopping_agent/config.py). The lock is per process, so StorefrontBackend cart methods enforce them too; eligibility, pricing, and inventory are the backend's in both roles.
  3. Nothing in either interface charges or places an order: checkout renders the cart (enrich_checkout in shopping_agent/enrichment.py) and the host completes it; post-purchase care is reads, with no cancel or refund tool.
  4. Provenance lives on the session state (ShoppingSessionState, MerchantSessionState), saved with the session when the request or turn ends (SessionStore in examples/demo_common/sessions.py, a versioned state document beside the transcript), so a request on another process loads it. Each map keeps its newest PROVENANCE_CAP records (remember in commerce_common/types.py); a dropped id needs a fresh read.
  5. A component is validated, its products, orders, metrics, or changes are joined from those records, and ids without provenance are dropped and reported (run_presentation in commerce_common/presentation.py; each role's enrichment.py; commerce-ui-tools).

Ground the answers that are figures or terms

  1. A terms question, an order question, or an unseen product id (GROUNDING_RULES in shopping_agent/grounding.py), or a performance question or an apply request with nothing staged (merchant_agent/grounding.py), starts from the matching read: first_forced_tool in commerce_common/grounding.py picks it, the Messages API runtimes force it with tool_choice, and the SDK runtimes prefetch it when the rule has a prefetch form (ground in commerce_common/agent_sdk.py; the terms rule has none); the hosted path has the prompt only.
  2. The lexicons are config tuples (policy_intent_terms, order_intent_terms, product_id_patterns, metrics_intent_terms, and their cues); a deployment appends its own words, a gate flag turns a rule off, and neither changes prompt bytes.
Show full SKILL.md (387 more words)Show less

Hold identity on the server

  1. Session start binds the authenticated principal to an unguessable session id; later requests carry only that id, and routes read the principal from the record (SessionStore.start and session_dependency in examples/demo_common/sessions.py). No request field or tool argument names a user, merchant, or operator; the MCP servers take the principal from their environment, a production server from its request.
  2. Whether the principal owns a record (order, ticket, listing), and whether the step a call depends on has happened, is the backend's check against its store; an id having provenance does not make it theirs or ready.

Bound what is remembered

  1. Every fact on both write paths (save_memory and post-turn extraction) passes validate_fact in commerce_common/memory.py: key of at most 64 characters, value of at most 200, one of the three MemoryCategory values, and the MemoryWriteFilter, which refuses identifier-shaped values by default; memory_blocked_patterns adds patterns, and a filter with checks replaces it (MemoryRuntime.build).
  2. Extraction reads the last exchange's user and assistant text (transcript_text in commerce_common/turn.py), and extract_and_store drops its batch when the subject was purged meanwhile; the Messages API runtimes run it (update_memory), the SDK host calls the runtime, and the hosted path writes through save_memory only.
  3. memory_retention_days (with_retention), MemoryStore.delete_fact, MemoryStore.clear, and enable_memory hold on every path without changing prompt or tool bytes; the examples expose read and delete routes (install_memory_routes in examples/demo_common/memory.py), and clear belongs in account deletion.
  4. The subject is the shopper's user_id or the operation's merchant_id (memory_subject in each role's executor.py).

Refuse in the result, and keep the surface fixed

  1. A held call returns a normal result naming its gate (ToolOutcome.held in commerce_common/streaming.py; the host's tool_result event carries status: blocked), a failure returns an error result, and execute never raises.
  2. The tool list is a function of the config: enable_web_search (default off) adds the tool, the SDK runtimes allow-list the registered names, and the manifests enable tools one by one.
  3. The reference MCP servers bind to loopback unless an environment variable states that an authenticating gateway is in front (enforce_local_only_bind in commerce_common/mcp_server.py).

Two rules for adversarial evals

  • Poisoned listings, reviews, and messages live in eval fixtures merged in for a run, outside demo and catalog data.
  • Every refusal case has a should-serve counterpart in the same niche, so a suite catches over-refusal too (commerce-evals).

© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/commerce-builder/skills/commerce-trust-safety of anthropics/commerce-agents.

Open the folder on GitHubat commit fd4d592

Compare with similar skills

Commerce Trust Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Commerce Trust Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Commerce Trust Safety this skillanthropics/commerce-agents3.2k—~1.8kAutomated safety check: PassApache-2.0
Third Party Cookiesthedaviddias/Front-End-Checklist74k—~580Automated safety check: PassMIT
Third Party Scriptsthedaviddias/Front-End-Checklist74k—~417Automated safety check: PassMIT
Managing Third Party Vendor Riskmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Audit Third Party Contractsben-manes/caffeine18k—~1.1kAutomated safety check: PassApache-2.0
Third Party Codeopen-edge-platform/anomalib6.2k—~599Automated safety check: PassApache-2.0

Similar skills

  • Third Party Cookies

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing a website for privacy compliance, third-party resource loading, or cookie consent implementation.

    74k GitHub stars~580 tokensUpdated 5 days ago
    Legal & ComplianceAuto-check passed
  • Third Party Scripts

    thedaviddias/Front-End-Checklist

    A skill your agent uses when auditing slow page loads, heavy assets, or rendering delays related to Optimize third-party script loading.

    74k GitHub stars~417 tokensUpdated 5 days ago
    Frontend & DesignAuto-check passed
  • Managing Third Party Vendor Risk

    mukul975/Anthropic-Cybersecurity-Skills

    Build and run a third-party/vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM: inventory and tier vendors, issue SIG/CAIQ questionnaires, review SOC 2/ISO 27001 evidence, set…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Audit Third Party Contracts

    ben-manes/caffeine

    Verify every third-party and sharp-edged JDK API usage against the contract the upstream documentation actually states

    18k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Third Party Code

    open-edge-platform/anomalib

    Review/generate third-party code attribution, licensing, and notice requirements

    6.2k GitHub stars~599 tokensUpdated yesterday
    Auto-check passed
  • Third Party Package Patches

    oracle/graalpython

    Official

    Create or update GraalPy third-party package and Rust crate compatibility patches under graalpython/lib-graalpython/patches, including PyPI source preparation, Cargo crate autopatching, rebasing…

    1.7k GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed

More from anthropics/commerce-agents

All 16 skills in this repo
  • Commerce Evals

    anthropics/commerce-agents

    Official

    Authoring and running behavioral evals for a shopping or merchant agent, covering the case shape, authoring rules, code graders and judges, the run pattern, and poisoned fixtures.

    3.2k GitHub stars~1.8k tokensUpdated 9 days ago
    Auto-check passed
  • Catalog Listings

    anthropics/commerce-agents

    Official

    Creating and improving listing content, covering titles, descriptions, attribute completeness, categorization fixes, image callouts written as text, edits written from material the operator…

    3.2k GitHub stars~1k tokensUpdated 9 days ago
    Auto-check passed
  • Commerce Architecture

    anthropics/commerce-agents

    Official

    How the reference commerce agents of either role are structured, covering the loop, where each rule lives, skills, the backend interface, delegates, and model fields.

    3.2k GitHub stars~1.7k tokensUpdated 9 days ago
    Auto-check passed
  • Commerce Merchant Operations

    anthropics/commerce-agents

    Official

    The reference merchant agent, covering its flows, staged changes and host approval, metrics grounding, the analysis delegate, store memory, components, and marketplace rules.

    3.2k GitHub stars~2.1k tokensUpdated 9 days ago
    Auto-check passed
  • Commerce Prompt Caching

    anthropics/commerce-agents

    Official

    The reference agents' cache-stable request assembly, covering the static system and per-request context split, the fixed tool list, the rolling conversation breakpoint, which config fields are…

    3.2k GitHub stars~2k tokensUpdated 9 days ago
    Auto-check passed
  • Commerce UI Tools

    anthropics/commerce-agents

    Official

    The reference presentation-tool contract, covering server-side enrichment, suggestion chips, the event stream, progressive rendering, both roles' built-in components, and adding a vertical component.

    3.2k GitHub stars~1.7k tokensUpdated 9 days ago
    Auto-check passed

Questions about Commerce Trust Safety

What does Commerce Trust Safety do?

The rules the reference agents enforce in code for third-party content, writes, grounding, identity, and memory, each with its module, plus two adversarial-eval rules. Commerce Trust Safety is an agent skill from anthropics/commerce-agents, published by the product's own GitHub organization. The rules the reference agents enforce in code for third-party content, writes, grounding, identity, and memory, each with its module, plus two adversarial-eval rules.

How do I install Commerce Trust Safety in Claude Code?

Run `npx skills add anthropics/commerce-agents --skill commerce-trust-safety -a claude-code`. Or copy the skill folder (plugins/commerce-builder/skills/commerce-trust-safety in anthropics/commerce-agents) into .claude/skills/commerce-trust-safety in your project. Claude Code loads it when a task matches its description.

How do I install Commerce Trust Safety in Codex?

Run `npx skills add anthropics/commerce-agents --skill commerce-trust-safety -a codex`. Or copy the skill folder (plugins/commerce-builder/skills/commerce-trust-safety in anthropics/commerce-agents) into .agents/skills/commerce-trust-safety in your project. Codex loads it when a task matches its description.

Can I use Commerce Trust Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/commerce-agents --skill commerce-trust-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/commerce-trust-safety, .gemini/skills/commerce-trust-safety, .github/skills/commerce-trust-safety and .opencode/skills/commerce-trust-safety in your project.

What does Commerce Trust Safety need to run?

SKILL.md names no scripts, command-line tools or credentials: Commerce Trust Safety is instructions for the agent only.

Does Commerce Trust Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Commerce Trust Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Commerce Trust Safety use?

Commerce Trust Safety is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Commerce Trust Safety use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Commerce Trust Safety?

Skills that share tags, products or a category with Commerce Trust Safety: Third Party Cookies (thedaviddias/Front-End-Checklist, 74k stars), Third Party Scripts (thedaviddias/Front-End-Checklist, 74k stars), Managing Third Party Vendor Risk (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Audit Third Party Contracts (ben-manes/caffeine, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Commerce Trust Safety?

anthropics (a GitHub organization, an official publisher) maintains it in anthropics/commerce-agents, which has 3,198 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 2, 2026.

Source: anthropics/commerce-agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.