Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add lunw/shopline-ai-toolkit-dsh --skill shopline-graphqlgit clone --depth 1 https://github.com/lunw/shopline-ai-toolkit-dshWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/lunw/shopline-ai-toolkit-dsh/shopline-graphql)<a href="https://agentmods.dev/skills/lunw/shopline-ai-toolkit-dsh/shopline-graphql"><img src="https://agentmods.dev/badge/skills/lunw/shopline-ai-toolkit-dsh/shopline-graphql/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/lunw/shopline-ai-toolkit-dsh/shopline-graphql"><img src="https://agentmods.dev/badge/skills/lunw/shopline-ai-toolkit-dsh/shopline-graphql.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00058 | $0.00886 |
| Opus 5 | $0.00029 | $0.00443 |
| Sonnet 5 | $0.00012 | $0.00177 |
| Haiku 4.5 | $0.00006 | $0.00089 |
Grade A, and why
shopline-graphql scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 66 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SHOPLINE GraphQL APIs (Admin + Storefront)
SHOPLINE exposes two GraphQL surfaces. Both use quarterly versions (vYYYYMMDD) and return HTTP 200 with errors embedded for most business failures.
Endpoints
| Surface | Endpoint |
|---|---|
| Admin GraphQL | POST https://{handle}.myshopline.com/admin/graph/{version}/graphql.json |
| Storefront GraphQL | POST https://{handle}.myshopline.com/storefront/graph/{version}/graphql.json |
Headers: Content-Type: application/json, Authorization: Bearer {accessToken} (Admin). Storefront calls use storefront customer access tokens — see the Storefront API docs; the schema is browsable in the docs Explorer (/graphql/storefront).
Global IDs
GraphQL objects are addressed by global IDs:
gid://shopline/{object_name}/{id}
e.g. gid://shopline/Customer/1. Query an object's global ID first, then reuse it in mutations and follow-up queries. Never fabricate IDs — always fetch them.
Query limits (Admin)
- Cost-point rate limiting: every request costs points; complex queries cost more. HTTP 429
Too many requestmeans you exceeded the budget — simplify the query or wait. - Max field nesting: 13 levels. A deeper query returns HTTP 200 with
"message": "maximum query depth exceeded 14 > 13"(extensions.classification: ExecutionAborted). - Keep selections minimal: only the fields you actually need (also cheaper).
Errors
Common business codes inside errors[].extensions.code (HTTP still 200):
| Code | Meaning |
|---|---|
REQUEST_LIMIT_EXCEEDED |
rate limited — retry later |
PARAM_ILLEGAL |
wrong parameter type/format |
DATA_NOT_EXIST |
the object does not exist |
REMOTE_ERROR / SYSTEM_ERROR / INNER_FAIL |
platform-side failures — retry |
TOO_MANY_REQUESTS |
wait minutes |
ACCESS_TOKEN_INVALID / ACCESS_TOKEN_IS_EXPIRED |
token problems — refresh (see shopline-oauth) |
| HTTP 402 | Store has been frozen or closed |
Generating & validating operations
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 66 lines · 58 tokens per session scan A af6d891b5f40
shopline-graphql is a skill published in the GitHub repository lunw/shopline-ai-toolkit-dsh (5 stars, last pushed 16d ago), licensed MIT. It adds 58 tokens to every session and 886 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
pipefy-api-fallback
Use this skill when an MCP tool fails AND the introspection skill could not resolve the problem. This is the last-resort fallback (Tier 3): call the Pipefy GraphQL API directly using curl or httpx, authenticating with the Service Account (OAuth2) or a Personal Access Token (PAT) available as env var. Follow the 3-tier…
pipefy-introspection
Use this skill when you need to discover GraphQL type shapes, mutation signatures, enum values, or execute arbitrary GraphQL as a fallback. This is the first fallback tier (Tier 2) when dedicated MCP tools fail or don't exist for an operation. 7 MCP tools.
yao-process
Yao process execution expert. ALWAYS invoke this skill when the user needs to call a Yao process, query data models, run scripts, or check process permissions. Do not call processes without checking this skill first.
daytona-cloud-server
Daytona cloud server, Den sandbox, desktop plus cloud e2e, marketplace server, worker proxy, cloud auth, org policies, connect Electron to Den. Use for server-side setup in validated flows.
stripe-billing-subscriptions
Analyze Stripe customers, subscriptions, prices, invoices, payment status, and lifecycle transitions with explicit environment and object scope.
kotlin-ktor-patterns
Ktor server patterns including routing DSL, plugins, authentication, Koin DI, kotlinx.serialization, WebSockets, and testApplication testing. Use when building a Ktor server — routing, plugins, auth, DI, serialization, or tests.