shopify-mcp-server

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and Shopify capabilities are broadly coherent, but the trust chain is weak: it asks the agent to run an unverified third-party `shopify-mcp` package/personal repo and forwards high-value Shopify credentials into it. No direct malicious exfiltration is documented, so this is not confirmed malware, but it is a high-risk supply-chain and credential-forwarding skill.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Sep 16, 2026, 07:36 AM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fshopify-mcp-server%2F@ba3d10c17a051769cb47641653ad21c3699d3a637a61f21643dd139ed646c1ba
Security Audit — socket — shopify-mcp-server