shopify-ai-toolkit-wrapper

Warn

Audited by Socket on Sep 9, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent and the data flows are mostly proportionate for a Shopify MCP integration, with no obvious exfiltration or malicious behavior. However, the skill's core install/config instruction is internally inconsistent with Shopify's current official package name, creating a meaningful supply-chain risk because it asks users to execute an npm package while admitting the name may be wrong.

Confidence: 93%Severity: 58%
AnomalyLOW
references/mcp-config.md

No direct malware is present in the supplied documentation. The principal risks are execution of an unpinned package via npx -y, use of an explicitly placeholder and potentially incorrect package name, and insecure persistence of Shopify tokens in ~/.bashrc. Verify the official package name and publisher, pin a reviewed version with integrity controls, avoid storing tokens in shell profiles, restrict token scopes, and validate the target store URL before use.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:51 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Fshopify-ai-toolkit-wrapper%2F@15326e96f558756a7ffcdefcd0581daa2848e7a0aa9f9a313137a75f721edd41
Security Audit — socket — shopify-ai-toolkit-wrapper