shopify-headless-commerce

Warn

Audited by Snyk on Feb 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a specialized, commerce-focused integration for the Shopify Storefront API that exposes write/mutation operations for carts, discounts, gift cards, checkout flow (producing a hosted checkout URL) and customer account/payment-related associations. Although payment is ultimately processed by Shopify's hosted checkout, the skill is explicitly designed to create/manage carts and drive the checkout/payment flow (including applying gift cards/discounts). This is a specific financial/ecommerce execution capability (not a generic tool), so it meets the "direct financial execution" threshold.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 27, 2026, 07:33 PM