Agent skill

Shopify Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Apply Shopify security best practices for API credentials, webhook HMAC validation, and access scope management.

MITAuto-check: notesBackend & APIs

Install Shopify Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace shopify-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/shopify-security-basics .claude/skills/shopify-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shopify-security-basics
GitHub stars
2.8k
Token cost
~1.3k tokens
SKILL.md length
400 words
Files
3 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Apply Shopify security best practices for API credentials, webhook HMAC validation, and access scope management.

  • Works in 5 steps: Secure Credential Storage → Webhook HMAC Verification → OAuth Request Verification → …
  • Securing API keys
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Calls git and brew; needs SHOPIFY_API_KEY and SHOPIFY_API_SECRET

What it does

Shopify Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply Shopify security best practices for API credentials, webhook HMAC validation, and access scope management. Use when securing API keys, validating webhook signatures, or auditing Shopify security configuration. Trigger with phrases like "shopify security", "shopify secrets", "secure shopify", "shopify HMAC", "shopify webhook verify".

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/oauth-request-verification.md` and `references/webhook-hmac-verification.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Webhooks and Security review. It works with Shopify. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Securing API keys
  • Validating webhook signatures
  • Auditing Shopify security configuration
  • With phrases like shopify security

Example prompts

  • “shopify security”
  • “shopify secrets”
  • “secure shopify”
  • “/shopify-security-basics”

Requirements

  • A credential in SHOPIFY_API_KEY
  • A credential in SHOPIFY_API_SECRET
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Grep

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Secure Credential Storage
  2. Webhook HMAC Verification
  3. OAuth Request Verification
  4. Minimal Access Scopes
  5. Content Security Policy for Embedded Apps

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • shopify.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SHOPIFY_API_KEY
    • SHOPIFY_API_SECRET
    • SHOPIFY_ACCESS_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Shopify Security Basics loads about 1.3k tokens when it runs, and up to ~1.9k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 400 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:44
    # .env — NEVER commit
  • NoteMentions a .env fileSKILL.md:50
    .env
  • NoteMentions a .env fileSKILL.md:51
    .env.local
  • NoteMentions a .env fileSKILL.md:52
    .env.*.local
  • NoteMentions a .env fileSKILL.md:135
    - [ ] `.env` files in `.gitignore`
  • NoteRuns commands with sudoSKILL.md:149
    # or: sudo apt install git-secrets  # Linux

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 400 words, ~1,328 tokens.

Download SKILL.mdSave it as .claude/skills/shopify-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
shopify-security-basics
description
Apply Shopify security best practices for API credentials, webhook HMAC validation, and access scope management. Use when securing API keys, validating webhook signatures, or auditing Shopify security configuration. Trigger with phrases like "shopify security", "shopify secrets", "secure shopify", "shopify HMAC", "shopify webhook verify".
allowed-tools
Read, Write, Grep
compatibility
Designed for Claude Code
version
2.7.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, ecommerce, shopify

Shopify Security Basics

Overview

Security essentials for Shopify apps: credential management, webhook HMAC validation, request verification, and least-privilege access scopes.

Prerequisites

  • Shopify Partner account with app credentials
  • Understanding of HMAC-SHA256 signatures
  • Access to Shopify app configuration

Instructions

Step 1: Secure Credential Storage
bash
# .env — NEVER commit
SHOPIFY_API_KEY=your_api_key
SHOPIFY_API_SECRET=your_api_secret_key
SHOPIFY_ACCESS_TOKEN=shpat_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

# .gitignore — add immediately
.env
.env.local
.env.*.local
*.pem

Token format reference:

Token TypePrefixLengthUsed For
Admin API access tokenshpat_38 charsServer-side Admin API
Storefront API tokenvariesvariesClient-safe storefront queries
API secret keynone32+ hexWebhook HMAC, OAuth
Step 2: Webhook HMAC Verification

Shopify signs every webhook with your app's API secret using HMAC-SHA256. The signature is in the X-Shopify-Hmac-Sha256 header. Use crypto.timingSafeEqual for comparison to prevent timing attacks. The middleware must use raw body parser (not JSON parser).

See Webhook HMAC Verification for the complete implementation.

Step 3: OAuth Request Verification

Verify that incoming OAuth requests from Shopify are authentic by checking the HMAC query parameter. The library handles this automatically, but the manual approach sorts params alphabetically, creates a query string, and compares HMAC hex digests.

See OAuth Request Verification for the complete implementation.

Step 4: Minimal Access Scopes

Only request the scopes your app actually needs:

Use CaseRequired Scopes
Read-only product catalogread_products
Product managementread_products, write_products
Order dashboardread_orders
Fulfillment automationread_orders, write_fulfillments, read_fulfillments
Customer loyalty appread_customers, write_customers
Full admin appRequest scopes incrementally, not all at once
toml
# shopify.app.toml — start minimal, add as needed
[access_scopes]
scopes = "read_products"

# Use optional scopes for features that not all merchants need
[access_scopes.optional]
scopes = "write_products,read_orders"
Step 5: Content Security Policy for Embedded Apps
typescript
// Embedded apps must set proper CSP headers
app.use((req, res, next) => {
  const shop = req.query.shop as string;
  res.setHeader(
    "Content-Security-Policy",
    `frame-ancestors https://${shop} https://admin.shopify.com;`
  );
  next();
});
Show full SKILL.md (168 more words)Show less

Output

  • Credentials securely stored in environment variables
  • Webhook HMAC verification on all incoming webhooks
  • OAuth request signatures validated
  • Minimal access scopes configured
  • CSP headers set for embedded apps

Error Handling

Security IssueDetectionMitigation
Token in git historygit log -p | grep shpat_Rotate token immediately, use git-secrets
Invalid webhook HMAC401 responses in webhook handlerVerify API secret matches Partner Dashboard
Missing scope403 errors on API callsAdd scope to shopify.app.toml and re-auth
Token exposed in client JSBrowser devtoolsNever send admin tokens to the browser

Examples

Security Audit Checklist
  • Access tokens in environment variables, never in code
  • .env files in .gitignore
  • Webhook HMAC verified on every incoming webhook
  • OAuth HMAC verified on app installation requests
  • Minimal scopes — only what the app needs
  • CSP frame-ancestors set for embedded apps
  • No admin tokens in client-side JavaScript
  • Token rotation procedure documented
  • git-secrets or similar pre-commit hook installed
Install git-secrets to Prevent Token Leaks
bash
# Install git-secrets
brew install git-secrets  # macOS
# or: sudo apt install git-secrets  # Linux

# Add Shopify patterns
git secrets --add 'shpat_[a-f0-9]{32}'
git secrets --add 'shpss_[a-f0-9]{32}'

# Install hook
git secrets --install

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/.curated/shopify-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/oauth-request-verification.md
  • references/webhook-hmac-verification.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Shopify Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Shopify Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Shopify Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: NotesMIT
Shopify Developmentdavila7/claude-code-templates33k7 repos~2.2kAutomated safety check: PassMIT
Shopify ExpertJeffallan/claude-skills12k—~1.8kAutomated safety check: PassMIT
Shopify Appsdavila7/claude-code-templates33k5 repos~310Automated safety check: PassMIT
Shopify Appssickn33/agentic-awesome-skills47k2 repos~359Automated safety check: PassMIT
Sec Checkwaynesutton/markdown-site627—~753Automated safety check: PassMIT

Similar skills

  • Shopify Development

    davila7/claude-code-templates

    Build Shopify apps, extensions, themes using GraphQL Admin API, Shopify CLI, Polaris UI, and Liquid.

    33k GitHub starsUsed in 7 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Shopify Expert

    Jeffallan/claude-skills

    Builds Shopify themes in Liquid, custom apps, Storefront API storefronts and checkout extensions, using the Shopify CLI to lint, run locally and deploy.

    12k GitHub stars~1.8k tokensUpdated 7 days ago
    Backend & APIsAuto-check passed
  • Shopify Apps

    davila7/claude-code-templates

    Expert patterns for Shopify app development including Remix/React Router apps, embedded apps with App Bridge, webhook handling, GraphQL Admin API, Polaris components, billing, and app extensions.

    33k GitHub starsUsed in 5 repos~310 tokens
    Backend & APIsAuto-check passed
  • Shopify Apps

    sickn33/agentic-awesome-skills

    Expert patterns for Shopify app development including Remix/React Router apps, embedded apps with App Bridge, webhook handling, GraphQL Admin API, Polaris components, billing, and app extensions.

    47k GitHub starsUsed in 2 repos~359 tokens
    Backend & APIsAuto-check passed
  • Sec Check

    waynesutton/markdown-site

    Security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code.

    627 GitHub stars~753 tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Bankr Shopify

    BankrBot/skills

    Shopify Admin & Storefront GraphQL APIs via curl, with Bankr-native bridges.

    1.2k GitHub stars~5.7k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Shopify Security Basics

What does Shopify Security Basics do?

Apply Shopify security best practices for API credentials, webhook HMAC validation, and access scope management. Shopify Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply Shopify security best practices for API credentials, webhook HMAC validation, and access scope management.

When should I use Shopify Security Basics?

Shopify Security Basics fits situations like: securing API keys; validating webhook signatures; auditing Shopify security configuration; with phrases like shopify security.

How do I install Shopify Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/shopify-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/shopify-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Shopify Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-security-basics -a codex`. Or copy the skill folder (skills/.curated/shopify-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/shopify-security-basics in your project. Codex loads it when a task matches its description.

Can I use Shopify Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shopify-security-basics, .gemini/skills/shopify-security-basics, .github/skills/shopify-security-basics and .opencode/skills/shopify-security-basics in your project.

What does Shopify Security Basics need to run?

Going by SKILL.md and its folder, Shopify Security Basics needs the command-line tools its instructions call (git and brew) and credentials named SHOPIFY_API_KEY, SHOPIFY_API_SECRET and SHOPIFY_ACCESS_TOKEN. Our summary lists: A credential in SHOPIFY_API_KEY; A credential in SHOPIFY_API_SECRET. Its frontmatter pre-approves these tools: Read, Write, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Shopify Security Basics access the network?

SKILL.md names 1 domain. As links in the text: shopify.dev. This is read from the text; nothing was executed.

Is Shopify Security Basics safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Shopify Security Basics use?

Shopify Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Shopify Security Basics use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 555 tokens, read only when the agent opens those files.

What are the alternatives to Shopify Security Basics?

Skills that share tags, products or a category with Shopify Security Basics: Shopify Development (davila7/claude-code-templates, 33k stars), Shopify Expert (Jeffallan/claude-skills, 12k stars), Shopify Apps (davila7/claude-code-templates, 33k stars) and Shopify Apps (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Shopify Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.