Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The script invokes external system commands to discover and drive the Shopify CLI via npm and node. While likely intended for legitimate Shopify administration, spawning external binaries expands the trust boundary and execution surface beyond simple alt-text processing; a malicious or tampered CLI path or globally installed package could cause unintended code execution under the user's privileges.
