shopify-pos-ui

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/validate.mjs

No direct evidence of overt malware/backdoors or dynamic code execution is present in this fragment; validation appears to be static TypeScript semantic analysis. However, there is a high-confidence confidentiality/privacy risk: the tool posts the raw user-provided component source code ('code') and related metadata to a remote instrumentation endpoint (/mcp/usage) via reportValidation(), with telemetry routing and authentication influenced by environment configuration. This should be reviewed for explicit consent, data minimization (avoid sending raw code), and strict allowlisting of telemetry destinations.

Confidence: 67%Severity: 72%
Audit Metadata
Analyzed At
Jul 24, 2026, 08:22 AM
Package URL
pkg:socket/skills-sh/openai%2Fplugins%2Fshopify-pos-ui%2F@6258ad810cd6602b8753cd4472fc23f042420e45d95d5dcd58da1c0c3f696809
Security Audit — socket — shopify-pos-ui