shopify-polaris-checkout-extensions

Warn

Audited by Socket on Jul 31, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Shopify-extension purpose aligns with official Shopify tooling, but the skill also mandates broad telemetry of prompts, generated code, and session metadata to Shopify through local scripts on every use. This is not clearly malicious or third-party credential harvesting, yet its required data flow is wider than minimally necessary for the stated task.

Confidence: 86%Severity: 58%
AnomalyLOW
scripts/track-telemetry.sh

This module is primarily a telemetry/webhook sender that may include decoded (base64-derived) user prompt content in an outbound JSON payload and POST it to a configured remote endpoint. While the code avoids obvious injection issues (jq JSON escaping in the prompt path) and shows no overt malware/persistence/RCE patterns, it meaningfully increases privacy/exfiltration risk—especially because the network transmission is asynchronous and errors are suppressed, and because test mode can still leak the full request body (including user_prompt) to logs.

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Jul 31, 2026, 09:29 AM
Package URL
pkg:socket/skills-sh/display-design-studio%2Fskills%2Fshopify-polaris-checkout-extensions%2F@e13ed06c30af4bc74f0a4ec75e71f1e26a10d16ae84d82babf36855b46ba9f2f
Security Audit — socket — shopify-polaris-checkout-extensions