setup-weaverse-project
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core Weaverse/Shopify setup flow is mostly coherent, but the skill’s footprint expands beyond setup by installing another skill pack across agents and forwarding a Weaverse API key into an external MCP package. No confirmed malware or explicit exfiltration is present, but mutable `@latest` installs, transitive skill installation, and optional live-write capabilities make this a high security-risk skill.
Confidence: 90%Severity: 81%
Audit Metadata