There is an unsigned grubx64.efi which needs those modules. If the user disables Secure Boot in yast2-bootloader, the boot option would be set to grubx64.efi instead of shim.efi.