shopify-onboarding-dev
Warn
Audited by Snyk on May 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill explicitly instructs installing the Shopify AI toolkit at runtime from GitHub (https://github.com/Shopify/Shopify-AI-Toolkit and https://github.com/Shopify/shopify-ai-toolkit), which fetches and installs remote code that will execute as a plugin/extension and can directly influence agent behavior, and the skill requires that plugin to proceed.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata