- i only speak liquid
- Posts
- "i only speak liquid" #84: AI-Powered Design-to-Code: Figma MCP Beta Revolutionizes Shopify Development
"i only speak liquid" #84: AI-Powered Design-to-Code: Figma MCP Beta Revolutionizes Shopify Development
Written by Vitalii (a Storetasker Expert)
Hey everyone,
This is Vitalii’s final edit of “i_only_speak_liquid”! 😭
Very sad - but don’t worry, we have another very talented Storetasker developer grabbing the mic in 2 weeks.
Vitalii! Thank you sir: such banging last 4 editions
#83: Shopify’s Next-Gen Dev Platform & Polaris Updates: What Developers Should Know
#84: AI-Powered Design-to-Code: Figma MCP Beta Revolutionizes Shopify Development. You’re reading it 😉
Stay in touch with Vitalii here & send him a thank you note if you liked his contributions.
—
Vitalii is a full-stack JavaScript and Shopify developer who’s worked with brands like CDLP and Represent.
He specializes in building high-performance Next.js and Remix storefronts, along with custom Shopify solutions that drive revenue and customer satisfaction.
Ofc: He’s an expert on Storetasker 😉 apply here.
Let’s dive in 🤿
What I’ve been thinking about:
AI-Powered Design-to-Code: Figma MCP Beta Revolutionizes Shopify Development
Hey Shopify friends,
What I've been thinking about this week is how the design-to-development gap is finally getting bridged in a meaningful way. After following the ecosystem closely, I've been watching how AI tools are reshaping our workflows, and this week's big news about Figma's MCP beta is exactly what we've been waiting for.
Figma MCP Server Beta Release
Figma just launched their Model Context Protocol (MCP) server beta, and it's a game-changer for Shopify developers. This tool lets AI agents like Cursor, VS Code, Windsurf, and Claude Code access design context directly from Figma files for precise code generation.
Key features:
AI-Powered Code Generation: Feeds rich design context - auto-layouts, typography, component hierarchies - to AI tools, generating Liquid templates in seconds
Code Connect Magic: Map Figma components directly to Liquid snippets, ensuring pixel-perfect consistency across themes
Remote Access: No Figma desktop app needed - connect via browser or IDEs for seamless workflows
Figma Make Integration: Extract interactions and animations, translate them into dynamic Liquid sections
Thoughts: This is huge for Liquid developers. The 80% faster UI builds that X devs are reporting for simple Shopify pages using Figma → MCP → Cursor workflows is exactly what we need heading into Q4. It's not perfect - complex UIs can trip up the AI - but for rapid prototyping, it's a game-changer.
Shopify's AI Commerce Push
Shopify announced a partnership with OpenAI allowing merchants to sell products directly within ChatGPT conversations, enabling seamless purchases without redirects. This feature is rolling out soon and aims to embed commerce into AI interactions.
Key updates:
Direct ChatGPT Sales: Merchants can sell single items directly in ChatGPT conversations
Stock Performance: Shopify's stock rose over 6% on the news
Strategic Alliance with ESW: Partnership for global expansion across 200+ markets
Platform Updates: New UI APIs for announcement bars, themeDuplicate mutation for easier theme copying
Thoughts: The timing is perfect. With Shopify pushing AI commerce and global scale, tools like Figma MCP become essential for developers who need to ship faster and adapt to these new touchpoints.
MCP Security Alert: First Malicious Server Steals Emails
The Model Context Protocol ecosystem just hit a major security milestone - and it's not the good kind. Cybersecurity researchers discovered the first-ever malicious MCP server in the wild, and it's a sobering wake-up call for all of us using these tools.
What happened:
Malicious npm Package: A developer named "phanpak" uploaded a rogue "postmark-mcp" package that copied the official Postmark Labs library
Stealthy Backdoor: Version 1.0.16 (released September 17) added a single line of code that BCC'd every email to "phan@giftshop[.]club"
Massive Impact: 1,643 downloads before the package was deleted, with emails being stolen for days
Simple but Effective: "One developer. One line of code. Thousands upon thousands of stolen emails."
The attack details:
Target: Email communications through MCP servers
Method: Legitimate-looking package with hidden backdoor functionality
Data Exposed: Password resets, invoices, customer communications, internal memos
Discovery: Found by Koi Security, package since deleted from npm
Thoughts: This was bound to happen, and it's a sobering reminder of the risks we face. The attack was embarrassingly simple but perfectly demonstrates how vulnerable the current MCP ecosystem is. MCP servers typically run with high trust and broad permissions, making them prime targets. For Shopify developers, this is especially concerning because we often handle sensitive customer data, payment information, and business communications.
What we need to do immediately:
Audit your MCP servers: Check every MCP tool you're using right now
Verify package sources: Only use MCP servers from verified, official sources
Rotate credentials: If you used any email-related MCP tools, rotate your credentials immediately
Review email logs: Check for suspicious BCC traffic to unknown domains
The fact that major players like OpenAI, Google DeepMind, and tools like Replit and Sourcegraph are adopting MCP is exciting, but this security incident reminds us we're still in the wild west phase of AI tooling. One developer, one line of code, thousands of stolen emails. Stay vigilant, folks.
3 links you can’t miss:
Shopify's OpenAI Integration – How AI is reshaping commerce
ESW Partnership for Global Expansion – Scaling internationally across 200+ markets
Figma MCP Catalog – Setup guides and supported tools
1 app I like:
Quotify – Streamline B2B and custom sales by generating professional quotes directly from your Shopify admin. Perfect for high-value products and pairs beautifully with MCP-generated product pages.
One learning as a freelancer:
The developers who are already experimenting with Figma MCP and AI tools are going to have a massive advantage in Q4. Clients are looking for faster delivery and more sophisticated integrations.
-Vitalii