shopify-developer

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a specialized Shopify development reference (not a generic tool) and explicitly documents programmatic commerce APIs: GraphQL Admin API endpoints, Storefront API, and Ajax cart endpoints (/cart/add.js, /cart/change.js). It also references Shopify objects like cart, order, customer and "cart operations via Ajax API" and shows example POSTs with access tokens. These are explicit, platform-specific APIs for manipulating carts/orders and interacting with a store's checkout state — i.e., programmatic e‑commerce operations that can be used to create/modify orders and affect payments. Therefore it grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 02:24 AM