shopify-store-setup-auditor

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the Shopify audit/fix scope is largely coherent and credentials are proportionate, but the forced silent `npx skills update` and transitive skill installation materially raise trust risk. Without the bundled script code, credential handling and exact network destinations cannot be fully verified.

Confidence: 82%Severity: 68%
AnomalyLOW
scripts/core/graphql.mjs

This module is primarily an integration utility for running Shopify GraphQL queries. It does not contain overt malicious payloads (no eval, no suspicious network beacons to arbitrary domains, no obvious system damage). However, it has two security-relevant trust-boundary issues: (1) resolveCli() can execute an arbitrary local script path when config.SKILL_HUB_SHOPIFY_CLI_JS is set to an existing file (node will run that path), which could enable arbitrary code execution if config is attacker-controlled; (2) config.storeInput is directly used in fetch() URLs without hostname allowlisting, creating a potential SSRF risk where sensitive credentials/tokens may be sent to unintended hosts. Overall, likely safe when config is fully trusted, but risky under untrusted configuration.

Confidence: 61%Severity: 62%
Audit Metadata
Analyzed At
Aug 26, 2026, 02:56 AM
Package URL
pkg:socket/skills-sh/lvsao%2Fshopify-skill-hub%2Fshopify-store-setup-auditor%2F@b1e5024dffee7b0eae0bafcd95ad803addf04e4d52fa4c31a9d6429059074c0d
Security Audit — socket — shopify-store-setup-auditor