shopify-advanced-troubleshooting
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalyreferences/layer-by-layer-diagnostic.md
LOWAnomalyLOW
references/layer-by-layer-diagnostic.md
The script appears intended for legitimate Shopify connectivity diagnostics and contains no clear embedded malware. However, it sends SHOPIFY_ACCESS_TOKEN to any host supplied through SHOPIFY_STORE. If that environment variable is attacker-controlled or mistyped, the token can be exfiltrated to an arbitrary domain. Validate and restrict STORE to the expected Shopify shop domain before making authenticated requests, and consider avoiding token transmission during connectivity-only tests.
Confidence: 98%Severity: 68%
Audit Metadata