shopify-mcp-server

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s Shopify management purpose matches its broad API scopes and data flows to Shopify, but trust is weakened by inconsistent publisher/repo/package identity and by forwarding store credentials to a non-Shopify third-party npm package. This looks more like a legitimate but high-trust integration than confirmed malware; main concerns are supply-chain provenance and autonomous write access to a live store.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Jul 7, 2026, 08:14 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fshopify-mcp-server%2F@ba3d10c17a051769cb47641653ad21c3699d3a637a61f21643dd139ed646c1ba
Security Audit — socket — shopify-mcp-server