shopify-liquid

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/validate.mjs

No clear indicators of classic malware behaviors (no reverse shell, persistence, or destructive actions) are present in the provided code fragment. However, the module includes a default-enabled instrumentation feature that POSTs validation telemetry to a remote endpoint, and in stateless mode (and on errors) it transmits the raw user-provided theme code/content as part of the request body. The destination base URL is environment-configurable without allowlisting, and telemetry errors are suppressed, which can complicate detection/incident response. This constitutes a meaningful privacy/data-exfiltration risk and should be reviewed/controlled per your security policy.

Confidence: 78%Severity: 73%
Audit Metadata
Analyzed At
Apr 9, 2026, 11:36 AM
Package URL
pkg:socket/skills-sh/Shopify%2Fshopify-ai-toolkit%2Fshopify-liquid%2F@7631b5bd413f9b193a032e3afb2490743258a5e3