MCP server for Shopify Admin API with a ComfyUI bridge for AI product image generation. Covers products, orders, inventory, and customers.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.COMFYUI_DEFAULT_CKPT— (no flag) sd_xl_base_1.0.safetensors Default checkpoint for bridge toolsCOMFYUI_PUBLIC_URL— comfyui-public-url same as --comfyui-url External URL used for image references passed to ShopifyCOMFYUI_URL— e =http://comfyui:8188 \MCP_HOST— host 0.0.0.0 Bind host (HTTP mode only)MCP_PORT— port 9110 Bind port (HTTP mode only)MCP_TRANSPORT— stdio =stdio (unset) Speak MCP over stdio instead of HTTP. Use when launched as a subprocess by a stdio-first MCP client (Claude Desktop, mcp-inspector).SHOPIFY_ACCESS_TOKEN— e =shpat_xxx \SHOPIFY_API_VERSION— shopify-api-version 2026-04 GraphQL Admin API versionSHOPIFY_STORE— e =your-store.myshopify.com \[](https://m8ven.ai/mcp/miller-joe-shopify-mcp-wkskrl)