{"id":"33038110-7956-4820-8af2-e3489a8f0a27","entityType":"agent","slug":"clawhub-maverick-maverick-shopify-mcp","name":"Shopify","canonicalUrl":"https://www.xpersona.co/agent/clawhub-maverick-maverick-shopify-mcp","canonicalPath":"/agent/clawhub-maverick-maverick-shopify-mcp","generatedAt":"2026-10-11T14:15:38.430Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T11:34:12.003Z","emptyReason":null},"description":"Search, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper. Use when the user asks about Shopify commerce ope... Skill: Shopify Owner: maverick Summary: Search, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper. Use when the user asks about Shopify commerce ope... Tags: latest:1.0.3 Version history: v1.0.3 | 2026-05-21T10:05:14.000Z | user Convert skill metadata frontmatter to YAML v1.0.2 | 2026-05-17T16:59:58.309Z | user Update mcporter setup and invocation contracts v1.0.1 | 20","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17b4scyfsybdcep8c0034pgs186087n:maverick-shopify-mcp","sourceUrl":"https://clawhub.ai/maverick/maverick-shopify-mcp","homepage":"https://clawhub.ai/maverick/skills/maverick-shopify-mcp","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/maverick/maverick-shopify-mcp","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/maverick/skills/maverick-shopify-mcp","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Search, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper. Use when the user asks about Shopify commerce ope..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T11:34:12.003Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T11:34:12.003Z","emptyReason":null},"stars":null,"forks":null,"downloads":1075,"packageName":null,"latestVersion":"1.0.3","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T11:34:11.930Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T11:34:12.003Z","lastCrawledAt":"2026-10-11T11:34:11.930Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T11:34:11.930Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.3","createdAt":"2026-05-21T10:05:14.000Z","changelog":"Convert skill metadata frontmatter to YAML","fileCount":6,"zipByteSize":6217},{"version":"1.0.2","createdAt":"2026-05-17T16:59:58.309Z","changelog":"Update mcporter setup and invocation contracts","fileCount":5,"zipByteSize":5012},{"version":"1.0.1","createdAt":"2026-05-14T11:58:51.750Z","changelog":"Refresh bearer token handling","fileCount":6,"zipByteSize":9881},{"version":"1.0.0","createdAt":"2026-05-05T18:49:47.470Z","changelog":"Initial release of maverick-shopify-mcp - Search, read, and interact with Shopify products, variants, catalogs, sellers, and checkout links via Shopify's MCP server. - Secure OAuth authentication with automatic token management and rotation. - CLI usage via `bash {baseDir}/scripts/invoke.sh`, with JSON output support and error handling. - Clear safety guidelines for write operations affecting customer-facing data. - Documents required dependencies and install steps (mcporter, jq, flock, shasum).","fileCount":6,"zipByteSize":5960}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17b4scyfsybdcep8c0034pgs186087n:maverick-shopify-mcp","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-maverick-maverick-shopify-mcp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-maverick-maverick-shopify-mcp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-maverick-maverick-shopify-mcp/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-maverick-maverick-shopify-mcp/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-maverick-maverick-shopify-mcp/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-maverick-maverick-shopify-mcp/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T14:15:38.429Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-maverick-maverick-shopify-mcp/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-maverick-maverick-shopify-mcp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-maverick-maverick-shopify-mcp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-maverick-maverick-shopify-mcp/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T11:34:12.003Z","emptyReason":null},"readme":"Skill: Shopify\n\nOwner: maverick\n\nSummary: Search, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper. Use when the user asks about Shopify commerce ope...\n\nTags: latest:1.0.3\n\nVersion history:\n\nv1.0.3 | 2026-05-21T10:05:14.000Z | user\n\nConvert skill metadata frontmatter to YAML\n\nv1.0.2 | 2026-05-17T16:59:58.309Z | user\n\nUpdate mcporter setup and invocation contracts\n\nv1.0.1 | 2026-05-14T11:58:51.750Z | user\n\nRefresh bearer token handling\n\nv1.0.0 | 2026-05-05T18:49:47.470Z | user\n\nInitial release of maverick-shopify-mcp\n\n- Search, read, and interact with Shopify products, variants, catalogs, sellers, and checkout links via Shopify's MCP server.\n- Secure OAuth authentication with automatic token management and rotation.\n- CLI usage via `bash {baseDir}/scripts/invoke.sh`, with JSON output support and error handling.\n- Clear safety guidelines for write operations affecting customer-facing data.\n- Documents required dependencies and install steps (mcporter, jq, flock, shasum).\n\nArchive index:\n\nArchive v1.0.3: 6 files, 6217 bytes\n\nFiles: agents/openai.yaml (252b), mcporter.json (330b), scripts/server.py (9253b), skill-card.md (2328b), SKILL.md (2964b), _meta.json (139b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: maverick-shopify-mcp\ndescription: Search, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper. Use when the user asks about Shopify commerce operations.\nmetadata:\n  openclaw:\n    emoji: \"🛍️\"\n    requires:\n      bins:\n        - mcporter\n        - uv\n      env:\n        - MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\n        - MAVERICK_SHOPIFY_MCP_SHOP\n    primaryEnv: MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\n    install:\n      - id: node\n        kind: node\n        package: mcporter\n        bins:\n          - mcporter\n        label: Install mcporter (node)\n      - id: brew-uv\n        kind: brew\n        formula: uv\n        bins:\n          - uv\n        label: Install uv (brew)\n---\n\n# Shopify\n\n## Quick start\n\nThis skill is a thin pass-through to a local stdio MCP server. mcporter spawns the skill's Python server on each call and passes the configured Shopify env vars to the subprocess.\n\n```sh\nmcporter --config {baseDir}/mcporter.json list maverick-shopify --schema\n```\n\nFor structured output:\n\n```sh\nmcporter --config {baseDir}/mcporter.json call --output json maverick-shopify.<tool> key=value\n```\n\n## Safety\n\nWrite operations that create, publish, update, or expose products, variants, orders, customers, or externally visible product links can affect customer-facing commerce flows. Confirm clear user intent before invoking write tools — search and read tools are safe to call freely while exploring. Search products before assuming product or variant IDs, and read product and variant details before recommending or linking items.\n\n## Authentication\n\nThe deployment harness provides a Shopify access token and shop identifier. mcporter passes them into the stdio subprocess via `mcporter.json`; the local server sends the token to Shopify as the admin API access token.\n\nThis skill does not claim a refresh-token contract for Shopify. If Shopify rejects the token, reconnect the integration so the deployment harness can provision a new access token.\n\n## Data flow\n\nTool calls run locally: mcporter spawns this skill's Python MCP server as a subprocess, and that server forwards Shopify Admin API requests with the configured access token. Shopify sees the product, order, customer, and shop data referenced by each call. Use this skill for Shopify-related work only; do not pass unrelated sensitive content through these tools.\n\n## Dependencies\n\n- **`mcporter`** ([github.com/steipete/mcporter](https://github.com/steipete/mcporter)) — MCP CLI used to invoke the local MCP server. Auto-installed via `npm install -g --ignore-scripts mcporter` if missing on PATH (see `install` spec in frontmatter). The install spec uses unpinned `mcporter` (npm `latest`); operators with strict supply-chain controls should override the install to pin a specific version.\n- **`uv`** ([docs.astral.sh/uv](https://docs.astral.sh/uv/)) — runs the Python wrapper and local MCP server from their inline dependency metadata.\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn734qkn0pkds34pv28ksc0p7h81ha6e\",\n  \"slug\": \"maverick-shopify-mcp\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1779357914000\n}\n\nFile v1.0.3:skill-card.md\n\n## Description:\n\nSearch, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[maverick](https://clawhub.ai/user/maverick)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nStore operators, support teams, and developers use this skill to inspect Shopify shop data and manage products, orders, and customers through agent-invoked MCP tools.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: A Shopify admin token and raw GraphQL or write tools can change products, orders, customers, or customer-facing store content.\n\nMitigation: Use a least-privilege Shopify token and require explicit user approval before product mutations, raw admin_graphql mutations, publishing, linking, or customer/order changes.\n\nRisk: The configured shop host can direct admin API calls to an unintended Shopify tenant if deployment configuration is wrong or insufficiently validated.\n\nMitigation: Validate and pin MAVERICK_SHOPIFY_MCP_SHOP to the intended myshopify.com tenant before installation or use.\n\nRisk: Unpinned dependency installation can introduce supply-chain drift across deployments.\n\nMitigation: Pin dependency versions for mcporter, uv, and Python dependencies in controlled environments.\n\n## Reference(s):\n\n- [ClawHub Shopify skill page](https://clawhub.ai/maverick/skills/maverick-shopify-mcp)\n- [Maverick publisher profile](https://clawhub.ai/user/maverick)\n- [mcporter](https://github.com/steipete/mcporter)\n- [uv documentation](https://docs.astral.sh/uv/)\n\n## Skill Output:\n\n**Output Type(s):** [API Calls, JSON, Guidance]\n\n**Output Format:** [JSON tool results from Shopify Admin API calls with concise natural-language guidance for the user]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [List-style tools bound requested limits between 1 and 100 results; write tools and raw GraphQL calls can change Shopify store data.]\n\n## Skill Version(s):\n\n1.0.3 (source: ClawHub release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.0.3:mcporter.json\n\n{\n  \"imports\": [],\n  \"mcpServers\": {\n    \"maverick-shopify\": {\n      \"command\": \"uv\",\n      \"args\": [\"run\", \"--script\", \"scripts/server.py\"],\n      \"env\": {\n        \"MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\": \"${MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN}\",\n        \"MAVERICK_SHOPIFY_MCP_SHOP\": \"${MAVERICK_SHOPIFY_MCP_SHOP}\"\n      }\n    }\n  }\n}\n\nFile v1.0.3:agents/openai.yaml\n\ninterface:\n  display_name: \"Shopify\"\n  short_description: \"Search and manage Shopify products, orders, customers, and shop data\"\n  default_prompt: \"Use the Shopify MCP tools to help the user inspect products, orders, customers, and Shopify shop data.\"\n\nArchive v1.0.2: 5 files, 5012 bytes\n\nFiles: agents/openai.yaml (252b), mcporter.json (330b), scripts/server.py (9253b), SKILL.md (3274b), _meta.json (139b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: maverick-shopify-mcp\ndescription: Search, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper. Use when the user asks about Shopify commerce operations.\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"emoji\": \"🛍️\",\n        \"requires\":\n          {\n            \"bins\": [\"mcporter\", \"uv\"],\n            \"env\":\n              [\n                \"MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\",\n                \"MAVERICK_SHOPIFY_MCP_SHOP\",\n              ],\n          },\n        \"primaryEnv\": \"MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\",\n        \"install\":\n          [\n            {\n              \"id\": \"node\",\n              \"kind\": \"node\",\n              \"package\": \"mcporter\",\n              \"bins\": [\"mcporter\"],\n              \"label\": \"Install mcporter (node)\",\n            },\n            {\n              \"id\": \"brew-uv\",\n              \"kind\": \"brew\",\n              \"formula\": \"uv\",\n              \"bins\": [\"uv\"],\n              \"label\": \"Install uv (brew)\",\n            },\n          ],\n      },\n  }\n---\n\n# Shopify\n\n## Quick start\n\nThis skill is a thin pass-through to a local stdio MCP server. mcporter spawns the skill's Python server on each call and passes the configured Shopify env vars to the subprocess.\n\n```sh\nmcporter --config {baseDir}/mcporter.json list maverick-shopify --schema\n```\n\nFor structured output:\n\n```sh\nmcporter --config {baseDir}/mcporter.json call --output json maverick-shopify.<tool> key=value\n```\n\n## Safety\n\nWrite operations that create, publish, update, or expose products, variants, orders, customers, or externally visible product links can affect customer-facing commerce flows. Confirm clear user intent before invoking write tools — search and read tools are safe to call freely while exploring. Search products before assuming product or variant IDs, and read product and variant details before recommending or linking items.\n\n## Authentication\n\nThe deployment harness provides a Shopify access token and shop identifier. mcporter passes them into the stdio subprocess via `mcporter.json`; the local server sends the token to Shopify as the admin API access token.\n\nThis skill does not claim a refresh-token contract for Shopify. If Shopify rejects the token, reconnect the integration so the deployment harness can provision a new access token.\n\n## Data flow\n\nTool calls run locally: mcporter spawns this skill's Python MCP server as a subprocess, and that server forwards Shopify Admin API requests with the configured access token. Shopify sees the product, order, customer, and shop data referenced by each call. Use this skill for Shopify-related work only; do not pass unrelated sensitive content through these tools.\n\n## Dependencies\n\n- **`mcporter`** ([github.com/steipete/mcporter](https://github.com/steipete/mcporter)) — MCP CLI used to invoke the local MCP server. Auto-installed via `npm install -g --ignore-scripts mcporter` if missing on PATH (see `install` spec in frontmatter). The install spec uses unpinned `mcporter` (npm `latest`); operators with strict supply-chain controls should override the install to pin a specific version.\n- **`uv`** ([docs.astral.sh/uv](https://docs.astral.sh/uv/)) — runs the Python wrapper and local MCP server from their inline dependency metadata.\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn734qkn0pkds34pv28ksc0p7h81ha6e\",\n  \"slug\": \"maverick-shopify-mcp\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1779037198309\n}\n\nFile v1.0.2:mcporter.json\n\n{\n  \"imports\": [],\n  \"mcpServers\": {\n    \"maverick-shopify\": {\n      \"command\": \"uv\",\n      \"args\": [\"run\", \"--script\", \"scripts/server.py\"],\n      \"env\": {\n        \"MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\": \"${MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN}\",\n        \"MAVERICK_SHOPIFY_MCP_SHOP\": \"${MAVERICK_SHOPIFY_MCP_SHOP}\"\n      }\n    }\n  }\n}\n\nFile v1.0.2:agents/openai.yaml\n\ninterface:\n  display_name: \"Shopify\"\n  short_description: \"Search and manage Shopify products, orders, customers, and shop data\"\n  default_prompt: \"Use the Shopify MCP tools to help the user inspect products, orders, customers, and Shopify shop data.\"\n\nArchive v1.0.1: 6 files, 9881 bytes\n\nFiles: agents/openai.yaml (252b), mcporter.json (208b), scripts/local_http_invoke.py (14399b), scripts/server.py (10358b), SKILL.md (3345b), _meta.json (139b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: maverick-shopify-mcp\ndescription: Search, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper. Use when the user asks about Shopify commerce operations.\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"emoji\": \"🛍️\",\n        \"requires\":\n          {\n            \"bins\": [\"mcporter\", \"uv\"],\n            \"env\":\n              [\n                \"MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\",\n                \"MAVERICK_SHOPIFY_MCP_SHOP\",\n              ],\n          },\n        \"primaryEnv\": \"MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\",\n        \"install\":\n          [\n            {\n              \"id\": \"node\",\n              \"kind\": \"node\",\n              \"package\": \"mcporter\",\n              \"bins\": [\"mcporter\"],\n              \"label\": \"Install mcporter (node)\",\n            },\n            {\n              \"id\": \"brew-uv\",\n              \"kind\": \"brew\",\n              \"formula\": \"uv\",\n              \"bins\": [\"uv\"],\n              \"label\": \"Install uv (brew)\",\n            },\n          ],\n      },\n  }\n---\n\n# Shopify\n\n## Quick start\n\nAlways invoke through the local HTTP wrapper. The wrapper starts this skill's local MCP server on loopback when needed, waits for readiness, and then calls `mcporter`.\n\n```sh\nuv run --script {baseDir}/scripts/local_http_invoke.py list maverick-shopify --schema\n```\n\nFor structured output:\n\n```sh\nuv run --script {baseDir}/scripts/local_http_invoke.py call --output json maverick-shopify.<tool> key=value\n```\n\n## Safety\n\nWrite operations that create, publish, update, or expose products, variants, orders, customers, or externally visible product links can affect customer-facing commerce flows. Confirm clear user intent before invoking write tools — search and read tools are safe to call freely while exploring. Search products before assuming product or variant IDs, and read product and variant details before recommending or linking items.\n\n## Authentication\n\nThe deployment harness provides a Shopify access token and shop identifier. mcporter forwards the access token as a static bearer token to the local MCP server; the local server sends it to Shopify as the admin API access token.\n\nThis skill does not claim a refresh-token contract for Shopify. If Shopify rejects the token, reconnect the integration so the deployment harness can provision a new access token.\n\n## Data flow\n\nTool calls travel from the agent to mcporter, then to this skill's local MCP server at `http://127.0.0.1:8763/mcp`. The local server forwards Shopify Admin API requests with the bearer token supplied on each MCP request. Shopify sees the product, order, customer, and shop data referenced by each call. Use this skill for Shopify-related work only; do not pass unrelated sensitive content through these tools.\n\n## Dependencies\n\n- **`mcporter`** ([github.com/steipete/mcporter](https://github.com/steipete/mcporter)) — MCP CLI used to invoke the local MCP server. Auto-installed via `npm install -g --ignore-scripts mcporter` if missing on PATH (see `install` spec in frontmatter). The install spec uses unpinned `mcporter` (npm `latest`); operators with strict supply-chain controls should override the install to pin a specific version.\n- **`uv`** ([docs.astral.sh/uv](https://docs.astral.sh/uv/)) — runs the Python wrapper and local MCP server from their inline dependency metadata.\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn734qkn0pkds34pv28ksc0p7h81ha6e\",\n  \"slug\": \"maverick-shopify-mcp\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1778759931750\n}\n\nFile v1.0.1:mcporter.json\n\n{\n  \"imports\": [],\n  \"mcpServers\": {\n    \"maverick-shopify\": {\n      \"baseUrl\": \"http://127.0.0.1:8763/mcp\",\n      \"transport\": \"http\",\n      \"bearerTokenEnv\": \"MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\"\n    }\n  }\n}\n\nFile v1.0.1:agents/openai.yaml\n\ninterface:\n  display_name: \"Shopify\"\n  short_description: \"Search and manage Shopify products, orders, customers, and shop data\"\n  default_prompt: \"Use the Shopify MCP tools to help the user inspect products, orders, customers, and Shopify shop data.\"\n\nArchive v1.0.0: 6 files, 5960 bytes\n\nFiles: agents/openai.yaml (263b), mcporter.json (184b), scripts/init-mcporter.sh (5541b), scripts/invoke.sh (708b), SKILL.md (4030b), _meta.json (139b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: maverick-shopify-mcp\ndescription: Search, read, and work with Shopify products, variants, catalog discovery, sellers, and checkout links via Shopify's configured MCP server (https://catalog.shopify.com/api/ucp/mcp). Use when the user asks about Shopify products, variants, sellers, catalog discovery, or checkout links.\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"emoji\": \"🛍️\",\n        \"requires\":\n          {\n            \"bins\": [\"mcporter\", \"jq\", \"flock\", \"shasum\"],\n            \"env\":\n              [\n                \"MAVERICK_SHOPIFY_MCP_REFRESH_TOKEN\",\n                \"MAVERICK_SHOPIFY_MCP_CLIENT_ID\",\n                \"MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\",\n              ],\n          },\n        \"primaryEnv\": \"MAVERICK_SHOPIFY_MCP_REFRESH_TOKEN\",\n        \"install\":\n          [\n            {\n              \"id\": \"node\",\n              \"kind\": \"node\",\n              \"package\": \"mcporter\",\n              \"bins\": [\"mcporter\"],\n              \"label\": \"Install mcporter (node)\",\n            },\n          ],\n      },\n  }\n---\n\n# Shopify\n\n## Quick start\n\nAlways invoke through `bash {baseDir}/scripts/invoke.sh` — never call `mcporter` directly. The wrapper seeds the OAuth vault from the env-supplied tokens when needed, then calls `mcporter`.\n\n```sh\nbash {baseDir}/scripts/invoke.sh list maverick-shopify --schema\n```\n\nFor structured output (also surfaces transport errors as JSON envelopes — workaround for mcporter [#153](https://github.com/steipete/mcporter/issues/153)):\n\n```sh\nbash {baseDir}/scripts/invoke.sh call --output json maverick-shopify.TOOL_NAME key=value | jq '.result.content'\n```\n\n## Safety\n\nWrite operations that create, publish, update, or expose products, variants, catalog data, seller records, checkout links, or externally visible product links can affect customer-facing commerce flows. Confirm clear user intent before invoking write tools — search and read tools are safe to call freely while exploring. Search products before assuming product or variant IDs, and read product and variant details before recommending or linking items.\n\n## Authentication\n\nTokens are provisioned and rotated automatically. If a call returns HTTP 401 that doesn't recover within a few seconds, the OAuth grant has been revoked — re-authorize the integration to refresh credentials.\n\n## Data flow\n\nTool calls travel to Shopify's configured MCP service at `https://catalog.shopify.com/api/ucp/mcp` over HTTPS, authenticated via OAuth. Shopify sees the product, variant, catalog, seller, and checkout-link data referenced by each call. Use this skill for Shopify-related work only; do not pass unrelated sensitive content through these tools.\n\n## Dependencies\n\n- **`mcporter`** ([github.com/steipete/mcporter](https://github.com/steipete/mcporter)) — MCP CLI used to invoke Shopify's configured MCP server. Auto-installed via `npm install -g --ignore-scripts mcporter` if missing on PATH (see `install` spec in frontmatter). The install spec uses unpinned `mcporter` (npm `latest`); operators with strict supply-chain controls should override the install to pin a specific version (e.g. `mcporter@<version>`).\n- **`jq`** ([stedolan.github.io/jq](https://stedolan.github.io/jq/)) — JSON processor used by the vault initializer. System dependency; install via your OS package manager (`apt install jq`, `brew install jq`, etc.).\n- **`flock`** (part of [util-linux](https://github.com/util-linux/util-linux)) — file locking used to serialize concurrent vault writes. Available by default on Linux; on macOS install via `brew install flock`.\n- **`shasum`** (Perl, ships with [`Digest::SHA`](https://metacpan.org/pod/Digest::SHA)) — computes the SHA-256 hashes used to derive the mcporter vault key and the provisioned-token marker. Preinstalled on macOS and on Debian/Ubuntu (incl. the deployed `cloudflare/sandbox` Ubuntu 22.04 image); on minimal Linux images install `perl-Digest-SHA`. The script invokes `shasum -a 256` rather than GNU `sha256sum` so it runs on stock macOS without `coreutils`.\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn734qkn0pkds34pv28ksc0p7h81ha6e\",\n  \"slug\": \"maverick-shopify-mcp\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1778006987470\n}\n\nFile v1.0.0:mcporter.json\n\n{\n  \"imports\": [],\n  \"mcpServers\": {\n    \"maverick-shopify\": {\n      \"baseUrl\": \"https://catalog.shopify.com/api/ucp/mcp\",\n      \"transport\": \"http\",\n      \"auth\": \"oauth\"\n    }\n  }\n}\n\nFile v1.0.0:agents/openai.yaml\n\ninterface:\n  display_name: \"Shopify\"\n  short_description: \"Search Shopify products, variants, catalogs, and checkout links\"\n  default_prompt: \"Use the Shopify MCP tools to help the user discover products, inspect variants, and reason about Shopify catalog data.\"","readmeExcerpt":"Skill: Shopify Owner: maverick Summary: Search, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper. Use when the user asks about Shopify commerce ope... Tags: latest:1.0.3 Version history: v1.0.3 | 2026-05-21T10:05:14.000Z | user Convert skill metadata frontmatter to YAML v1.0.2 | 2026-05-17T16:59:58.309Z | user Update mcporter setup and invocation contracts v1.0.1 | 20","codeSnippets":[],"executableExamples":[{"language":"sh","snippet":"mcporter --config {baseDir}/mcporter.json list maverick-shopify --schema"},{"language":"sh","snippet":"mcporter --config {baseDir}/mcporter.json call --output json maverick-shopify.<tool> key=value"},{"language":"sh","snippet":"mcporter --config {baseDir}/mcporter.json list maverick-shopify --schema"},{"language":"sh","snippet":"mcporter --config {baseDir}/mcporter.json call --output json maverick-shopify.<tool> key=value"},{"language":"sh","snippet":"uv run --script {baseDir}/scripts/local_http_invoke.py list maverick-shopify --schema"},{"language":"sh","snippet":"uv run --script {baseDir}/scripts/local_http_invoke.py call --output json maverick-shopify.<tool> key=value"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: maverick-shopify-mcp\ndescription: Search, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper. Use when the user asks about Shopify commerce operations.\nmetadata:\n  openclaw:\n    emoji: \"🛍️\"\n    requires:\n      bins:\n        - mcporter\n        - uv\n      env:\n        - MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\n        - MAVERICK_SHOPIFY_MCP_SHOP\n    primaryEnv: MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\n    install:\n      - id: node\n        kind: node\n        package: mcporter\n        bins:\n          - mcporter\n        label: Install mcporter (node)\n      - id: brew-uv\n        kind: brew\n        formula: uv\n        bins:\n          - uv\n        label: Install uv (brew)\n---\n\n# Shopify\n\n## Quick start\n\nThis skill is a thin pass-through to a local stdio MCP server. mcporter spawns the skill's Python server on each call and passes the configured Shopify env vars to the subprocess.\n\n```sh\nmcporter --config {baseDir}/mcporter.json list maverick-shopify --schema\n```\n\nFor structured output:\n\n```sh\nmcporter --config {baseDir}/mcporter.json call --output json maverick-shopify.<tool> key=value\n```\n\n## Safety\n\nWrite operations that create, publish, update, or expose products, variants, orders, customers, or externally visible product links can affect customer-facing commerce flows. Confirm clear user intent before invoking write tools — search and read tools are safe to call freely while exploring. Search products before assuming product or variant IDs, and read product and variant details before recommending or linking items.\n\n## Authentication\n\nThe deployment harness provides a Shopify access token and shop identifier. mcporter passes them into the stdio subprocess via `mcporter.json`; the local server sends the token to Shopify as the admin API access token.\n\nThis skill does not claim a refresh-token contract for Shopify. If Shopify rejects the token, reconnect the integration so the deployment harness can provision a new access token.\n\n## Data flow\n\nTool calls run locally: mcporter spawns this skill's Python MCP server as a subprocess, and that server forwards Shopify Admin API requests with the configured access token. Shopify sees the product, order, customer, and shop data referenced by each call. Use this skill for Shopify-related work only; do not pass unrelated sensitive content through these tools.\n\n## Dependencies\n\n- **`mcporter`** ([github.com/steipete/mcporter](https://github.com/steipete/mcporter)) — MCP CLI used to invoke the local MCP server. Auto-installed via `npm install -g --ignore-scripts mcporter` if missing on PATH (see `install` spec in frontmatter). The install spec uses unpinned `mcporter` (npm `latest`); operators with strict supply-chain controls should override the install to pin a specific version.\n- **`uv`** ([docs.astral.sh/uv](https://docs.astral.sh/uv/)) — runs the Python wrapper and local MCP server from their inline dependency metadata."},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn734qkn0pkds34pv28ksc0p7h81ha6e\",\n  \"slug\": \"maverick-shopify-mcp\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1779357914000\n}"},{"path":"skill-card.md","content":"## Description:\n\nSearch, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[maverick](https://clawhub.ai/user/maverick)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nStore operators, support teams, and developers use this skill to inspect Shopify shop data and manage products, orders, and customers through agent-invoked MCP tools.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: A Shopify admin token and raw GraphQL or write tools can change products, orders, customers, or customer-facing store content.\n\nMitigation: Use a least-privilege Shopify token and require explicit user approval before product mutations, raw admin_graphql mutations, publishing, linking, or customer/order changes.\n\nRisk: The configured shop host can direct admin API calls to an unintended Shopify tenant if deployment configuration is wrong or insufficiently validated.\n\nMitigation: Validate and pin MAVERICK_SHOPIFY_MCP_SHOP to the intended myshopify.com tenant before installation or use.\n\nRisk: Unpinned dependency installation can introduce supply-chain drift across deployments.\n\nMitigation: Pin dependency versions for mcporter, uv, and Python dependencies in controlled environments.\n\n## Reference(s):\n\n- [ClawHub Shopify skill page](https://clawhub.ai/maverick/skills/maverick-shopify-mcp)\n- [Maverick publisher profile](https://clawhub.ai/user/maverick)\n- [mcporter](https://github.com/steipete/mcporter)\n- [uv documentation](https://docs.astral.sh/uv/)\n\n## Skill Output:\n\n**Output Type(s):** [API Calls, JSON, Guidance]\n\n**Output Format:** [JSON tool results from Shopify Admin API calls with concise natural-language guidance for the user]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [List-style tools bound requested limits between 1 and 100 results; write tools and raw GraphQL calls can change Shopify store data.]\n\n## Skill Version(s):\n\n1.0.3 (source: ClawHub release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."},{"path":"mcporter.json","content":"{\n  \"imports\": [],\n  \"mcpServers\": {\n    \"maverick-shopify\": {\n      \"command\": \"uv\",\n      \"args\": [\"run\", \"--script\", \"scripts/server.py\"],\n      \"env\": {\n        \"MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN\": \"${MAVERICK_SHOPIFY_MCP_ACCESS_TOKEN}\",\n        \"MAVERICK_SHOPIFY_MCP_SHOP\": \"${MAVERICK_SHOPIFY_MCP_SHOP}\"\n      }\n    }\n  }\n}"},{"path":"agents/openai.yaml","content":"interface:\n  display_name: \"Shopify\"\n  short_description: \"Search and manage Shopify products, orders, customers, and shop data\"\n  default_prompt: \"Use the Shopify MCP tools to help the user inspect products, orders, customers, and Shopify shop data.\""}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Search, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper. Use when the user asks about Shopify commerce ope... Skill: Shopify Owner: maverick Summary: Search, read, and work with Shopify products, orders, customers, and shop data through a local MCP wrapper. Use when the user asks about Shopify commerce ope... Tags: latest:1.0.3 Version history: v1.0.3 | 2026-05-21T10:05:14.000Z | user Convert skill metadata frontmatter to YAML v1.0.2 | 2026-05-17T16:59:58.309Z | user Update mcporter setup and invocation contracts v1.0.1 | 20","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1193,"uniquenessScore":47,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T11:34:12.003Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T11:34:12.003Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:15:38.430Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}