shopify
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a specific integration for Shopify — an e-commerce platform that includes payment processing and order/transaction management. The exposed actions include Create Order, Create Draft Order, Update Order (and Get Order), and the proxy feature lets callers call arbitrary Shopify API endpoints. These are explicit, purpose-built e-commerce/payment-related operations (not generic browser automation or a general HTTP caller) and therefore allow direct financial execution (creating/updating orders and invoking payment/transaction endpoints).
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata