{"id":17061,"plugin_id":"plugins_6a701c7b1f9481919cf7c7448ddc1bd4","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:13:56.562Z","digest":"ee175a7447b8f6d31ffcc9298d858dd0d6809680bc339ba99d23eb28087a0cbd","against":null,"payload":{"description":"Use at the start of any Shopify app engineering, debugging, review, launch, listing, or growth task. Routes the request to the smallest relevant Shopify App Builder skills and enforces credential, verification, deployment, publication, and paid-spend boundaries. Triggers include: 'Shopify app', 'Shopify extension', 'Shopify API', 'App Bridge', 'Polaris', 'Built for Shopify', 'App Store listing', and 'Shopify app ads'.","included_files":[],"name":"using-shopify-app-builder","skill_md_contents":"---\nname: using-shopify-app-builder\ndescription: \"Use at the start of any Shopify app engineering, debugging, review, launch, listing, or growth task. Routes the request to the smallest relevant Shopify App Builder skills and enforces credential, verification, deployment, publication, and paid-spend boundaries. Triggers include: 'Shopify app', 'Shopify extension', 'Shopify API', 'App Bridge', 'Polaris', 'Built for Shopify', 'App Store listing', and 'Shopify app ads'.\"\n---\n\n# Using Shopify App Builder\n\nTreat this skill as the router for the toolkit. Select focused skills before proposing code or operational changes.\n\n## Routing workflow\n\n1. Inspect the repository, framework, Shopify configuration, and the user's stated outcome.\n2. Classify the request with the routing table below.\n3. Read the selected skill files completely. Use the smallest set that covers the request.\n4. Verify time-sensitive platform behavior against current official Shopify documentation.\n5. Implement only what the user authorized, then run proportionate checks on the real affected surface.\n\n## Skill routing table\n\n| Request | Start with | Add when needed |\n| --- | --- | --- |\n| New app, scaffold, extension, or deployment plan | `shopify-cli` | `app-validation`, `app-niche-finder`, `app-auth`, `app-billing` |\n| Admin data or GraphQL error | `admin-graphql` | `metafields-metaobjects`, `webhooks`, `dev-troubleshooting` |\n| Legacy REST migration | `admin-rest` | `admin-graphql`, `migrate-rest-to-graphql` command in Claude/Cursor |\n| OAuth, token exchange, HMAC, or session issue | `app-auth` | `dev-troubleshooting`, `webhooks` |\n| Billing, plans, trials, or usage charges | `app-billing` | `app-pricing-strategy`, `merchant-pain-prevention` |\n| Embedded admin UI | `app-bridge` and `polaris-ui` | `ux-polaris-antipatterns`, `app-accessibility`, `app-performance` |\n| Storefront or theme work | `storefront-api`, `hydrogen-storefront`, or `liquid-themes` | `metafields-metaobjects` |\n| Checkout or backend customization | `shopify-functions` | `admin-graphql`, `dev-troubleshooting` |\n| Webhook delivery or signature verification | `webhooks` | `app-auth`, `dev-troubleshooting` |\n| Pre-ship or App Store review | `built-for-shopify-standards` | `merchant-pain-prevention`, `app-accessibility`, `app-performance`, UX skills |\n| Listing, name, price, or market validation | `app-listing-optimization`, `app-naming`, `app-pricing-strategy`, or `app-validation` | `app-niche-finder` |\n| App Store advertising | `shopify-app-store-ads` | `app-listing-optimization`, `app-pricing-strategy` |\n| Shopify MCP or agentic commerce | `shopify-mcp` | Relevant API and authentication skills |\n\n## Operating guidelines\n\n- Inspect first. Do not assume the app template, API version, package version, scopes, or deployment provider.\n- Use official Shopify documentation as the authority for unstable platform facts.\n- Keep OAuth scopes minimal and explain every requested write scope.\n- Treat GraphQL HTTP success separately from GraphQL `errors`, mutation `userErrors`, and throttle metadata.\n- Verify webhooks with the raw request body and constant-time HMAC comparison.\n- Never expose, echo, commit, or publish tokens, app secrets, session data, `.env` contents, or personal filesystem paths.\n- Do not deploy, publish, submit, alter billing, or enable paid advertising unless the user explicitly authorizes that action.\n- Preserve unrelated work in dirty repositories and avoid destructive cleanup.\n- Report live evidence for deployments and dashboard changes; source edits or a passing build alone are not proof of live success.\n\n## Harness behavior\n\n- Claude Code can use the bundled slash commands and specialist agents in addition to skills.\n- Codex and OpenCode should invoke focused skills by name or natural-language intent; Claude-specific agents are optional reference material, not native subagents.\n- Cursor can load the native plugin surfaces or the portable skills collection.\n- Gemini CLI receives this routing policy through `GEMINI.md` and reads focused `SKILL.md` files as needed.\n- Command Code and other Agent Skills-compatible harnesses use the portable skills collection.\n\n## Completion gate\n\nBefore reporting success, state what changed, which checks ran, what live surface was verified, and what remains unverified. Never convert an inference into a completion claim.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}