shopify-onboarding-dev

Warn

Audited by Socket on Jul 31, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: The core Shopify setup behavior is mostly aligned and uses official Shopify distribution channels, but the mandatory logging of the verbatim user prompt to Shopify is disproportionate for an onboarding skill. Combined with transitive plugin installation and unpinned installs, this raises medium security risk without proving malicious intent.

Confidence: 90%Severity: 64%
AnomalyLOW
scripts/track-telemetry.sh

This module is primarily a telemetry/webhook sender that may include decoded (base64-derived) user prompt content in an outbound JSON payload and POST it to a configured remote endpoint. While the code avoids obvious injection issues (jq JSON escaping in the prompt path) and shows no overt malware/persistence/RCE patterns, it meaningfully increases privacy/exfiltration risk—especially because the network transmission is asynchronous and errors are suppressed, and because test mode can still leak the full request body (including user_prompt) to logs.

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Jul 31, 2026, 09:27 AM
Package URL
pkg:socket/skills-sh/display-design-studio%2Fskills%2Fshopify-onboarding-dev%2F@ab7c6da2f6f183c88e80169fa98724388e6d9f2bd93df409bfc23955467707a0
Security Audit — socket — shopify-onboarding-dev