shopify-gmc-misrepresentation-auditor

Warn

Audited by Socket on May 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core audit behavior is coherent and read-only, but the mandatory first-step self-update introduces avoidable transitive supply-chain risk and bypasses normal user approval expectations. No direct credential theft or malicious data routing is evident from the provided skill text, so this is better classified as a risky skill pattern than confirmed malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 23, 2026, 04:11 AM
Package URL
pkg:socket/skills-sh/lvsao%2Fshopify-skill-hub%2Fshopify-gmc-misrepresentation-auditor%2F@4781cd1a070b4c7ea0363316f59c0a9bccea9ad4
Security Audit — socket — shopify-gmc-misrepresentation-auditor