shopify-mcp-server
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose and Shopify capabilities are broadly coherent, but the trust chain is weak: it asks the agent to run an unverified third-party `shopify-mcp` package/personal repo and forwards high-value Shopify credentials into it. No direct malicious exfiltration is documented, so this is not confirmed malware, but it is a high-risk supply-chain and credential-forwarding skill.
Confidence: 89%Severity: 84%
Audit Metadata