shopify-automation
Warn
Audited by Socket on Aug 31, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities match Shopify automation, so purpose alignment is mostly coherent, but it routes sensitive store data and OAuth-backed actions through a third-party hosted MCP layer instead of direct Shopify APIs. The install path is more a remote-service trust issue than a malware signal, yet the combination of broad business-action capability, mediated data flow, and inconsistent setup/auth naming makes this higher-risk than a normal documentation skill.
Confidence: 84%Severity: 68%
Audit Metadata