shopify-expert

Fail

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The file 'references/performance-optimization.md' includes a code example for JavaScript optimization that dynamically creates a script tag pointing to 'https://third-party.com/widget.js'. This domain is explicitly identified as malicious (Botnet) in security alerts.
  • [REMOTE_CODE_EXECUTION]: By advising users to inject the flagged script into their frontend code, the skill facilitates a remote code execution vector. This allows a known-malicious external source to execute arbitrary JavaScript within the context of the user's Shopify store, potentially compromising customer data and site integrity.
  • [DYNAMIC_EXECUTION]: The skill demonstrates and promotes the use of 'document.createElement' to load external code at runtime. This pattern is a high-risk execution method that can be leveraged to introduce malicious payloads while bypassing static analysis of the website's source code.
Recommendations
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — shopify-expert