optimize-shopify-image-alt

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/shopify-alt-text-admin.mjs

No strong evidence of intentional malware in the provided code. The primary security concern is arbitrary code execution via execFileAsync(process.execPath, ...) running a resolved @shopify/cli run.js entrypoint from the host environment. If SKILL_HUB_SHOPIFY_CLI_JS or the resolved global/AppData installation is tampered with, an attacker could achieve code execution when this tool runs. Network and file download behavior is constrained to Shopify CDN domains and temp directories, and there is no eval/dynamic execution of untrusted strings beyond the CLI entrypoint execution.

Confidence: 61%Severity: 55%
Audit Metadata
Analyzed At
Aug 24, 2026, 07:05 AM
Package URL
pkg:socket/skills-sh/lvsao%2Fshopify-skill-hub%2Foptimize-shopify-image-alt%2F@ff03cad47993668c4e05a465723263bbfcb38e0fd698ee17e373a68f39bd8aaf
Security Audit — socket — optimize-shopify-image-alt