setup-weaverse-project

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core Weaverse/Shopify setup flow is mostly coherent, but the skill’s footprint expands beyond setup by installing another skill pack across agents and forwarding a Weaverse API key into an external MCP package. No confirmed malware or explicit exfiltration is present, but mutable `@latest` installs, transitive skill installation, and optional live-write capabilities make this a high security-risk skill.

Confidence: 90%Severity: 81%
Audit Metadata
Analyzed At
Aug 21, 2026, 06:45 AM
Package URL
pkg:socket/skills-sh/weaverse%2Fshopify-hydrogen-skills%2Fsetup-weaverse-project%2F@63e342cedfd4ebc555f787bcbe140244f3dfeab35eb1f3315300e3f5e29f7c00
Security Audit — socket — setup-weaverse-project