shopify
Audited by Socket on Aug 1, 2026
2 alerts found:
Anomalyx2No clear malware/backdoor behavior is evident in this module. However, the script performs a runtime npm install when node_modules is missing (supply-chain risk) and can POST validation results to a remote endpoint (network/privacy risk). The core validation uses TypeScript semantic diagnostics rather than executing the user-provided code, reducing direct code-execution risk.
SUSPICIOUS. The stated Shopify developer purpose is plausible and the described capabilities are mostly coherent, but the install instructions are inconsistent with the official Shopify path in the supplied evidence and the skill primarily bootstraps other skills, adding supply-chain and transitive-trust risk. No direct credential harvesting, exfiltration endpoint, or malicious execution behavior is evident in the provided fragment.