shopify-hydrogen
Warn
Audited by Snyk on May 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a Shopify Hydrogen storefront cookbook explicitly exposing cart mutation functions (cart.create, cart.addLines, cart.updateLines, cart.updateGiftCardCodes, etc.) and a ShopPayButton component. These are specific e‑commerce payment/checkout primitives tied to Shopify's payment flow (Shop Pay) and mutations that lead to checkout/payment actions. Because it includes explicit, platform-specific payment/checkout capabilities (Shop Pay) and cart mutations that directly affect purchase/payment state, it meets the "specific tools to move money" criterion.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata