Token导航 LogoToken导航TokenDH.com
研究检索敏感数据clawhub未标认证来源可访问clear审计提醒

shopify-runtimeShopify runtime 搜索

Agent Skill

shopify-runtime 用于查找、检索和筛选相关信息,适合在 OpenClaw 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

3,320

周安装

133

GitHub Stars

1

下载量

1,075
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:shopify-runtime(Shopify runtime 搜索)
来源仓库:https://github.com/ypyf/shopify-runtime
安装命令:
openclaw skills install shopify-runtime
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install shopify-runtime

简介

直接访问已配置 Shopify 商店运行环境的交互接口。

  • 适合调试前端脚本、检查设置状态或查找官方文档。
  • 可在沙箱环境中执行 JavaScript 并查看即时反馈。
  • 仅限授权账户使用,禁止对非自有商店执行操作。
  • 部分高级功能可能需要额外权限申请才能启用。shopify-runtime 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

name
shopify-runtime
description
Use when the user wants direct Shopify runtime access through one configured store: inspect setup status, search Shopify docs, or execute JavaScript against the configured store.
metadata
{"openclaw":{"requires":{"env":["SHOPIFY_STORE_DOMAIN","SHOPIFY_CLIENT_ID","SHOPIFY_CLIENT_SECRET"]},"primaryEnv":"SHOPIFY_CLIENT_SECRET"}}

Seller Runtime Toolkit

Use this skill when you need direct, scriptable access to one Shopify store from OpenClaw.

This skill complements seller-api-workflow. Keep the existing workflow skill for higher-level business asks. Use this skill when the task is explicitly about Shopify setup status, documentation search, script execution, or troubleshooting those surfaces.

This skill is self-contained. You can copy the entire shopify-runtime/ folder into an OpenClaw workspace/skills/ directory and run it there without the seller-assistant plugin repository beside it.

Quick Start

  • Configure the skill in OpenClaw instead of maintaining per-store profiles.
  • Set this skill's apiKey in OpenClaw. Because the skill declares primaryEnv: "SHOPIFY_CLIENT_SECRET", OpenClaw injects that value into SHOPIFY_CLIENT_SECRET for each agent run.
  • Set skills.entries."shopify-runtime".env.SHOPIFY_STORE_DOMAIN to your *.myshopify.com domain.
  • Set skills.entries."shopify-runtime".env.SHOPIFY_CLIENT_ID to your Shopify app client id.
  • Optionally set skills.entries."shopify-runtime".env.SHOPIFY_API_VERSION to override the default API version.
  • Run the bundled script with node.
  • Read references/shopify-provider.md when the request touches auth, scopes, orders, or write access.
  • Read references/runtime-contract.md when you need the output shape or command examples.

Example OpenClaw config:

{
  skills: {
    entries: {
      "shopify-runtime": {
        apiKey: { source: "env", provider: "default", id: "SHOPIFY_CLIENT_SECRET" },
        env: {
          SHOPIFY_STORE_DOMAIN: "your-store.myshopify.com",
          SHOPIFY_CLIENT_ID: "your_shopify_client_id",
          SHOPIFY_API_VERSION: "2026-01",
        },
      },
    },
  },
}

Auth And Scope Notes

  • This skill currently authenticates with Shopify by exchanging SHOPIFY_CLIENT_ID + SHOPIFY_CLIENT_SECRET for an Admin API access token. It does not use a pre-issued SHOPIFY_ACCESS_TOKEN.
  • This flow is intended for a Shopify app owned by the same organization as the target store and installed on that same store.
  • Read operations usually need matching Shopify Admin API scopes such as read_products, read_inventory, read_orders, or read_customers.
  • Write operations usually need the matching write scopes such as write_products, write_inventory, or write_orders.
  • Order access can still fail even with basic scopes. Older orders may require read_all_orders, and protected customer data access may still be required.

Capability Boundaries

  • Prefer Admin GraphQL for normal reads and writes. Use REST only when GraphQL is not the best fit.
  • --mode read blocks local REST writes and GraphQL mutations before the request is sent.
  • --mode write only removes the local read-only guard. Shopify still enforces the app's granted scopes.
  • status confirms local skill readiness, not that Shopify token exchange will succeed.

Commands

Inspect current setup

Use this when the user asks whether the skill is ready, which store it is pointed at, or which API version it will use.

node skills/shopify-runtime/scripts/seller-runtime.mjs status

Search provider and official docs

Use this before writing an API script from memory. Prefer provider notes and the narrowest matching official documentation entry.

node skills/shopify-runtime/scripts/seller-runtime.mjs search --query "orders graphql pagination"

Add --limit or --refresh when needed.

Execute JavaScript

Use this after you know the request shape. Default to --mode read. Only use --mode write when the user clearly asked for a write operation and the Shopify token should allow it.

cat <<'EOF' | node skills/shopify-runtime/scripts/seller-runtime.mjs execute --mode read
return await provider.graphql(`
  query {
    shop {
      name
    }
  }
`)
EOF

The script body should use provider.graphql(...) or provider.request(...). In this runtime, provider.graphql(...) returns the validated GraphQL data object directly. Prefer piping the script on stdin so you do not need temporary files. --script-file is still supported when a real file is more convenient.

Working Rules

  • This skill targets one configured Shopify store per agent run.
  • Search docs before inventing request shapes or filters from memory.
  • Keep execution scripts narrow and return concise structured objects instead of raw payloads when possible.
  • Treat requestSummary, rawResponses, and logs as execution evidence when you explain the outcome.
  • Read mode blocks REST write methods and GraphQL mutations locally. Write mode still depends on the Shopify token having matching Admin API access.
  • The runtime reads SHOPIFY_STORE_DOMAIN, SHOPIFY_CLIENT_ID, SHOPIFY_CLIENT_SECRET, and optional SHOPIFY_API_VERSION from the environment that OpenClaw injects for the skill run.

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

79.78%
按下载量换算858

安全审计

VirusTotal

可疑

ClawScan

通过

Static analysis

可疑

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills