shopify-pos-ui

Warn

Audited by Socket on May 2, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/validate.mjs

This appears to be a legitimate TypeScript-based validator, but it contains two notable security risks: (1) it exfiltrates the submitted source code and metadata to an external endpoint via reportValidation() over HTTPS by default (unless OPT_OUT_INSTRUMENTATION=true); and (2) it reads an arbitrary local file path provided via --file without sandboxing. No direct malware behaviors (reverse shells, eval, command execution) are evident in the provided fragment.

Confidence: 78%Severity: 72%
Audit Metadata
Analyzed At
May 2, 2026, 04:37 PM
Package URL
pkg:socket/skills-sh/Shopify%2Fshopify-ai-toolkit%2Fshopify-pos-ui%2F@6bd26bb1f8128bf9ed448c15fc9c53ebb66e5d3f