shopify-merchant-onboarding
Warn
Audited by Socket on Apr 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose fits Shopify onboarding, but this local skill is mostly a stub that delegates execution to mutable remote instructions. Because the agent must fetch and exactly follow external SKILL.md files, the main risk is transitive trust and unreviewed remote behavior rather than confirmed malicious intent.
Confidence: 83%Severity: 62%
Audit Metadata