Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/untitled-developers/shopify-mcp/agents-mdgit clone --depth 1 https://github.com/untitled-developers/shopify-mcpWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00784 | $0.00784 |
| Opus 5 | $0.00392 | $0.00392 |
| Sonnet 5 | $0.00157 | $0.00157 |
| Haiku 4.5 | $0.00078 | $0.00078 |
Grade A, and why
shopify-mcp AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 45 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agent Instructions
This is a TypeScript CommonJS MCP server for the Shopify Admin API. Keep changes small, typed, and consistent with the existing tool-registration pattern.
Commands
npm installinstalls dependencies; this repo uses npm and has a committedpackage-lock.json.npm run buildcompilessrc/todist/withtsc.npm testruns the Vitest suite once.npm run devstarts the MCP server fromsrc/index.tsthroughts-node.npm run get-tokenruns the OAuth helper after a build, usingdist/get-token.js.
Project Map
- README.md has setup, MCP client configuration, environment variables, and the public tool list. Link to it instead of duplicating setup docs.
- src/index.ts is the stdio MCP entry point and registers every tool group.
- src/shopify-client.ts is the shared Shopify Admin GraphQL client. Prefer extending it over creating ad hoc fetch logic.
- src/config.ts loads
.envfrom the MCP host working directory first, then from the package directory.SHOPIFY_API_VERSIONdefaults to2026-01. - src/auth.ts currently requires
SHOPIFY_ACCESS_TOKEN; Partner Dashboard OAuth token acquisition lives in src/get-token.ts. - src/tools/ contains one module per tool group, each exporting
registerXxxTools(server, client). - tests/ contains Vitest tests for config, auth, the Shopify client, and tool registration.
Coding Conventions
- Use strict TypeScript and keep
.jsextensions in relative imports, even when importing.tssource files. - Tool names are global MCP names in
snake_case; check tests/tools.test.ts to avoid collisions. - Define tool parameters with Zod schemas and useful
.describe()text for MCP clients. - Use Admin GraphQL for Shopify API operations. Do not add non-GraphQL Shopify API calls unless Shopify has no GraphQL equivalent and the limitation is documented.
- Return MCP tool results as
{ content: [{ type: "text", text: JSON.stringify(value, null, 2) }] }unless the existing tool group uses a clearer plain-text success message. - Treat numeric Shopify IDs as strings at tool boundaries. When GraphQL needs GIDs, follow existing tools that accept either a GID or numeric ID and normalize internally.
- Keep stdout reserved for MCP JSON-RPC. Send diagnostics to stderr with the existing
[shopify-mcp]style.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 45 lines · 784 tokens per session scan A c73b3c28a4ed
shopify-mcp AGENTS.md is an instructions file published in the GitHub repository untitled-developers/shopify-mcp (0 stars, last pushed 2mo ago), licensed MIT. It adds 784 tokens to every session, about $0.0039 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
open-supermarkets AGENTS.md
Instructions for abracadabra50/open-supermarkets, covering agent integration guide, supported frameworks, quick integration, 1. add as skill and 2. agent calls commands.
eShopLite copilot-instructions.md
Instructions for Azure-Samples/eShopLite, covering eshoplite copilot instructions, project overview, architecture & patterns, critical workflows and project-specific conventions.
armornglory-mcp-server CLAUDE.md
Claude Code instructions for ArmorNGlory/armornglory-mcp-server, covering claude desktop & claude code guidelines (armornglory mcp), 1. role & identity, 2. interaction protocol and 3. claude desktop configuration.
subscription-patterns AGENTS.md
AGENTS.md instructions for commet-labs/subscription-patterns, covering subscription patterns and skills.
shopify-operations-mcp AGENTS.md
AGENTS.md instructions for jpka/shopify-operations-mcp, covering agents.md, working conventions and agent docs.
gengeo-agent-registry AGENTS.md
Instructions for warwickwood-cell/gengeo-agent-registry: GenGEO provides machine-readable merchant verification infrastructure for AI agents.