shopify

Warn

Audited by Socket on Aug 1, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
shopify-skills-test/.agents/skills/shopify-hydrogen/scripts/validate.js

No clear malware/backdoor behavior is evident in this module. However, the script performs a runtime npm install when node_modules is missing (supply-chain risk) and can POST validation results to a remote endpoint (network/privacy risk). The core validation uses TypeScript semantic diagnostics rather than executing the user-provided code, reducing direct code-execution risk.

Confidence: 70%Severity: 50%
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated Shopify developer purpose is plausible and the described capabilities are mostly coherent, but the install instructions are inconsistent with the official Shopify path in the supplied evidence and the skill primarily bootstraps other skills, adding supply-chain and transitive-trust risk. No direct credential harvesting, exfiltration endpoint, or malicious execution behavior is evident in the provided fragment.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Aug 1, 2026, 01:45 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fshopify%2F@a940110a947486b361779e4afb20e10576155eb1c7ae0edddb81bf873e005f8b
Security Audit — socket — shopify