shopify-automation

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities match Shopify automation, so purpose alignment is mostly coherent, but it routes sensitive store data and OAuth-backed actions through a third-party hosted MCP layer instead of direct Shopify APIs. The install path is more a remote-service trust issue than a malware signal, yet the combination of broad business-action capability, mediated data flow, and inconsistent setup/auth naming makes this higher-risk than a normal documentation skill.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Aug 31, 2026, 08:40 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fshopify-automation%2F@e7f14f1b70dce364e3dddde0351364fb1c59b6488b0a101e39f05099ab935aec
Security Audit — socket — shopify-automation