io.github.miller-joe/shopify-mcp

MCPattested
v0.1.2io.github.miller-joeUnknownUpdated 5mo agonpmGitHub

MCP server for Shopify Admin API with a ComfyUI bridge for AI product image generation.

MCP server for Shopify. Full Admin GraphQL API tooling plus an AI-driven product creation bridge via ComfyUI image generation. Every other Shopify MCP is a plain Admin API wrapper. This one pairs with @miller-joe/comfyui-mcp so you can say things like: "Create a product called 'Nebula Dreamer'. Generate a cosmic abstract image for it, description matching the vibe, tagged astrology, status…

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
5mo agoLast update
Package
Authorio.github.miller-joe
LicenseUnknown
Version0.1.2
Sourcemcp-registry
Trust Status
A
85/100Trusted
✓Listed in Forge index+10/10
✓Identity verified · attested build+20/20
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm maintainer match+0/5
→ Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain—
Provenance✓ Sigstore-verified · 5d049e5
Dependencies✓ 60 resolved+ · none vulnerable
Tool surface40 tools · 6 privileged
Security scan✓ Cleanv0.2.0 · 3mo agoHow well does this scan work?
EvalsNone
IndexedJun 13, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · 6 privileged
Statically extracted from the published packagev0.2.0 · 3mo ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

run_shopifyql_queryNo description published

This tool published no description. Forge does not invent one.

generate_and_create_productNo description published

This tool published no description. Forge does not invent one.

generate_product_imageNo description published

This tool published no description. Forge does not invent one.

refine_product_imageNo description published

This tool published no description. Forge does not invent one.

bulk_regenerate_imagesNo description published

This tool published no description. Forge does not invent one.

list_collectionsNo description published

This tool published no description. Forge does not invent one.

get_collectionNo description published

This tool published no description. Forge does not invent one.

create_collectionNo description published

This tool published no description. Forge does not invent one.

update_collectionNo description published

This tool published no description. Forge does not invent one.

delete_collectionprivilegedNo description published

This tool published no description. Forge does not invent one.

add_products_to_collectionNo description published

This tool published no description. Forge does not invent one.

remove_products_from_collectionprivilegedNo description published

This tool published no description. Forge does not invent one.

add_tagsNo description published

This tool published no description. Forge does not invent one.

remove_tagsprivilegedNo description published

This tool published no description. Forge does not invent one.

list_customersNo description published

This tool published no description. Forge does not invent one.

create_customerNo description published

This tool published no description. Forge does not invent one.

update_customerNo description published

This tool published no description. Forge does not invent one.

list_draft_ordersNo description published

This tool published no description. Forge does not invent one.

get_draft_orderNo description published

This tool published no description. Forge does not invent one.

create_draft_orderNo description published

This tool published no description. Forge does not invent one.

update_draft_orderNo description published

This tool published no description. Forge does not invent one.

complete_draft_orderNo description published

This tool published no description. Forge does not invent one.

delete_draft_orderprivilegedNo description published

This tool published no description. Forge does not invent one.

list_fulfillment_ordersNo description published

This tool published no description. Forge does not invent one.

get_fulfillment_orderNo description published

This tool published no description. Forge does not invent one.

get_fulfillmentNo description published

This tool published no description. Forge does not invent one.

create_fulfillmentNo description published

This tool published no description. Forge does not invent one.

update_fulfillment_trackingNo description published

This tool published no description. Forge does not invent one.

cancel_fulfillmentNo description published

This tool published no description. Forge does not invent one.

set_inventory_quantityNo description published

This tool published no description. Forge does not invent one.

list_locationsNo description published

This tool published no description. Forge does not invent one.

set_metafieldNo description published

This tool published no description. Forge does not invent one.

list_metafieldsNo description published

This tool published no description. Forge does not invent one.

delete_metafieldprivilegedNo description published

This tool published no description. Forge does not invent one.

list_metaobject_definitionsNo description published

This tool published no description. Forge does not invent one.

list_metaobjectsNo description published

This tool published no description. Forge does not invent one.

get_metaobjectNo description published

This tool published no description. Forge does not invent one.

create_metaobjectNo description published

This tool published no description. Forge does not invent one.

update_metaobjectNo description published

This tool published no description. Forge does not invent one.

delete_metaobjectprivilegedNo description published

This tool published no description. Forge does not invent one.

0 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

MCP server for Shopify. Full Admin GraphQL API tooling plus an AI-driven product creation bridge via ComfyUI image generation. Every other Shopify MCP is a plain Admin API wrapper. This one pairs with @miller-joe/comfyui-mcp so you can say things like: "Create a product called 'Nebula Dreamer'. Generate a cosmic abstract image for it, description matching the vibe, tagged astrology, status draft." Claude then runs ComfyUI, gets an image back, creates the Shopify product, and attaches the image,…

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This package was last scanned before Forge began storing the resolved tree. The next scan will record it.

Topics

Related in payments & commerce