shopify-advanced-troubleshooting

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/layer-by-layer-diagnostic.md

The script appears intended for legitimate Shopify connectivity diagnostics and contains no clear embedded malware. However, it sends SHOPIFY_ACCESS_TOKEN to any host supplied through SHOPIFY_STORE. If that environment variable is attacker-controlled or mistyped, the token can be exfiltrated to an arbitrary domain. Validate and restrict STORE to the expected Shopify shop domain before making authenticated requests, and consider avoiding token transmission during connectivity-only tests.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:53 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Fshopify-advanced-troubleshooting%2F@124e60bc7aedbe81c416893a497402a0d47284458b273c68e4025ffa262ef04a
Security Audit — socket — shopify-advanced-troubleshooting