Agent skill

Shopify Policy Guardrails

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Implement Shopify app policy enforcement with ESLint rules for API key detection, query cost budgets, and App Store compliance checks.

MITAuto-check: notesAI & LLM Engineering

Install Shopify Policy Guardrails

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-policy-guardrails -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace shopify-policy-guardrails --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/shopify-policy-guardrails .claude/skills/shopify-policy-guardrails && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shopify-policy-guardrails
GitHub stars
2.8k
Token cost
~1k tokens
SKILL.md length
280 words
Files
5 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Implement Shopify app policy enforcement with ESLint rules for API key detection, query cost budgets, and App Store compliance checks.

  • Works in 5 steps: Secret Detection Rules → Query Cost Budget Enforcement → Pre-Commit Hooks → …
  • Hardening a Shopify app against secret leaks
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Calls git

What it does

Shopify Policy Guardrails is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement Shopify app policy enforcement with ESLint rules for API key detection, query cost budgets, and App Store compliance checks. Use when hardening a Shopify app against secret leaks, enforcing query cost limits, or preparing for App Store submission review. Trigger with phrases like "shopify policy", "shopify lint", "shopify guardrails", "shopify compliance", "shopify eslint", "shopify app review".

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/ci-policy-pipeline.md`, `references/compliance-checker.md` and `references/query-cost-budget.md`). Compatibility notes: Designed for Claude Code

It sits in AI & LLM Engineering, covering App store release, Linting and formatting and LLM guardrails. It works with Shopify and ESLint. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Hardening a Shopify app against secret leaks
  • Enforcing query cost limits
  • Preparing for App Store submission review
  • With phrases like shopify policy

Example prompts

  • “shopify policy”
  • “shopify lint”
  • “shopify guardrails”
  • “/shopify-policy-guardrails”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(npx:*)

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Secret Detection Rules
  2. Query Cost Budget Enforcement
  3. Pre-Commit Hooks
  4. App Store Compliance Checker
  5. CI Policy Pipeline

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(npx:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • eslint.org
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Shopify Policy Guardrails loads about 1k tokens when it runs, and up to ~2.8k if it reads all its reference files. Until then it costs about 109 tokens; SKILL.md has 280 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:56
    ed changes for Shopify tokens and block `.env` files from being committed.
  • NoteMentions a .env fileSKILL.md:74
    name: Check .env not staged
  • NoteMentions a .env fileSKILL.md:78
    echo "ERROR: .env file staged for commit"

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 280 words, ~1,031 tokens.

Download SKILL.mdSave it as .claude/skills/shopify-policy-guardrails/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
shopify-policy-guardrails
description
Implement Shopify app policy enforcement with ESLint rules for API key detection, query cost budgets, and App Store compliance checks. Use when hardening a Shopify app against secret leaks, enforcing query cost limits, or preparing for App Store submission review. Trigger with phrases like "shopify policy", "shopify lint", "shopify guardrails", "shopify compliance", "shopify eslint", "shopify app review".
allowed-tools
Read, Write, Edit, Bash(npx:*)
compatibility
Designed for Claude Code
version
2.7.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, ecommerce, shopify

Shopify Policy & Guardrails

Overview

Automated policy enforcement for Shopify apps: secret detection, query cost budgets, App Store compliance checks, and CI policy validation.

Prerequisites

  • ESLint configured in project
  • Pre-commit hooks infrastructure
  • CI/CD pipeline with GitHub Actions
  • Shopify app with shopify.app.toml

Instructions

Step 1: Secret Detection Rules

Custom ESLint rule that catches hardcoded Shopify tokens (shpat_*, shpss_*) and API secrets in string literals and template literals.

See Secret Detection ESLint for the complete rule implementation.

Step 2: Query Cost Budget Enforcement

Static analysis of GraphQL queries enforcing budgets: max 100 items per first: param, max 3 levels of nesting, and max 500 estimated cost. Runs at build/test time.

See Query Cost Budget for the complete implementation.

Step 3: Pre-Commit Hooks

Git hooks that scan staged changes for Shopify tokens and block .env files from being committed.

yaml
# .pre-commit-config.yaml
repos:
  - repo: local
    hooks:
      - id: shopify-token-scan
        name: Scan for Shopify tokens
        language: system
        entry: bash -c '
          if git diff --cached --diff-filter=d | grep -E "shpat_[a-f0-9]{32}|shpss_[a-f0-9]{32}" ; then
            echo "ERROR: Shopify access token detected in staged changes"
            exit 1
          fi'
        pass_filenames: false

      - id: shopify-env-check
        name: Check .env not staged
        language: system
        entry: bash -c '
          if git diff --cached --name-only | grep -E "^\.env$|^\.env\.local$|^\.env\.production$" ; then
            echo "ERROR: .env file staged for commit"
            exit 1
          fi'
        pass_filenames: false
Step 4: App Store Compliance Checker

Pre-submission script that validates all three GDPR webhooks, token hygiene, CSP headers, and API version stability.

See Compliance Checker for the complete implementation.

Step 5: CI Policy Pipeline

GitHub Actions workflow enforcing token scanning, GDPR webhook configuration, and API version stability on every push and PR.

See CI Policy Pipeline for the complete workflow.

Output

  • ESLint rules catching hardcoded tokens
  • Query cost budgets enforced
  • Pre-commit hooks blocking secret leaks
  • App Store compliance checker
  • CI policy pipeline preventing violations

Error Handling

IssueCauseSolution
False positive on tokenBase64 string matchedNarrow regex pattern
Query cost estimate wrongComplex variable nestingUse actual debug header in tests
Pre-commit bypassed--no-verify flagEnforce in CI as backup
App Store rejectionMissing GDPR webhookRun compliance checker before submit

Examples

Quick Policy Scan
bash
# One-liner: check for token leaks in staged changes
git diff --cached | grep -E "shpat_|shpss_" && echo "TOKEN LEAK!" || echo "Clean"

# Check GDPR compliance
grep -c "customers/data_request\|customers/redact\|shop/redact" shopify.app.toml
# Should output: 3

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/.curated/shopify-policy-guardrails of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/ci-policy-pipeline.md
  • references/compliance-checker.md
  • references/query-cost-budget.md
  • references/secret-detection-eslint.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Shopify Policy Guardrails next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Shopify Policy Guardrails compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Shopify Policy Guardrails this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: NotesMIT
Existing Repoalinaqi/maggy707—~4kAutomated safety check: NotesMIT
LobeHub Alint Rule Set Maintenancelobehub/lobehub83k—~1.9kAutomated safety check: PassCustom licence
ShopifyShopify/Shopify-AI-Toolkit592—~4.2kAutomated safety check: PassMIT
Publish App Store VersionKeeForge/KeeForge117—~3.5kAutomated safety check: PassGPL-3.0
Testflightkmworks/kmreader113—~403Automated safety check: PassMIT

Similar skills

  • Existing Repo

    alinaqi/maggy

    Analyze existing repositories, maintain structure, setup guardrails and best practices

    707 GitHub stars~4k tokensUpdated 17 days ago
    DevelopmentAuto-check: notes
  • Maintains LobeHub's model-backed alint rule set: writing rules, removing false positives against real code, deciding warn versus error and tracking token cost.

    83k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Shopify

    Shopify/Shopify-AI-Toolkit

    Official

    Build anything on Shopify. An agent skill from Shopify/Shopify-AI-Toolkit.

    592 GitHub stars~4.2k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Publish App Store Version

    KeeForge/KeeForge

    Prepare and publish an already-built KeeForge iOS or macOS version through the App Store Connect API using an API key.

    117 GitHub stars~3.5k tokensUpdated today
    MobileAuto-check passed
  • Testflight

    kmworks/kmreader

    Distribute KMReader builds to TestFlight groups via the asc CLI.

    113 GitHub stars~403 tokensUpdated today
    MobileAuto-check passed
  • Auto Harness

    PacificStudio/openase

    Diagnose and strengthen a repository's harness layer: AGENTS.md rules, knowledge layout, architecture boundaries, lint and type gates, API and generated-client contracts, test scaffolding…

    268 GitHub stars~1.2k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Shopify Policy Guardrails

What does Shopify Policy Guardrails do?

Implement Shopify app policy enforcement with ESLint rules for API key detection, query cost budgets, and App Store compliance checks. Shopify Policy Guardrails is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement Shopify app policy enforcement with ESLint rules for API key detection, query cost budgets, and App Store compliance checks.

When should I use Shopify Policy Guardrails?

Shopify Policy Guardrails fits situations like: hardening a Shopify app against secret leaks; enforcing query cost limits; preparing for App Store submission review; with phrases like shopify policy.

How do I install Shopify Policy Guardrails in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-policy-guardrails -a claude-code`. Or copy the skill folder (skills/.curated/shopify-policy-guardrails in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/shopify-policy-guardrails in your project. Claude Code loads it when a task matches its description.

How do I install Shopify Policy Guardrails in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-policy-guardrails -a codex`. Or copy the skill folder (skills/.curated/shopify-policy-guardrails in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/shopify-policy-guardrails in your project. Codex loads it when a task matches its description.

Can I use Shopify Policy Guardrails in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-policy-guardrails -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shopify-policy-guardrails, .gemini/skills/shopify-policy-guardrails, .github/skills/shopify-policy-guardrails and .opencode/skills/shopify-policy-guardrails in your project.

What does Shopify Policy Guardrails need to run?

Going by SKILL.md and its folder, Shopify Policy Guardrails needs the command-line tools its instructions call (git). Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(npx:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Shopify Policy Guardrails access the network?

SKILL.md names 2 domains. As links in the text: eslint.org and github.com. This is read from the text; nothing was executed.

Is Shopify Policy Guardrails safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Shopify Policy Guardrails use?

Shopify Policy Guardrails is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Shopify Policy Guardrails use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Shopify Policy Guardrails?

Skills that share tags, products or a category with Shopify Policy Guardrails: Existing Repo (alinaqi/maggy, 707 stars), LobeHub Alint Rule Set Maintenance (lobehub/lobehub, 83k stars), Shopify (Shopify/Shopify-AI-Toolkit, 592 stars) and Publish App Store Version (KeeForge/KeeForge, 117 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Shopify Policy Guardrails?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.