Back to skill

Security audit

Ecom Manager D2c

Security checks for vulnerabilities and agentic risk

Overview

This ecommerce automation skill is coherent, but it needs review because it can change live store, advertising, messaging, and content systems without clearly defined authorization and approval controls.

Review this skill before installing on a live store. Use only least-privilege API tokens, connect only trusted messaging channels with verified identities, require explicit owner approval for every price, inventory, content, discount, messaging, and ad-spend change, set budget and rate limits outside the agent, and ensure competitor monitoring complies with applicable terms and laws.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
commands.md:3
Finding

Chat-Originated Commands Can Trigger Privileged Store Operations Without Defined User Authorization

Content
View full analysis

Vulnerability Details

File Locations:

  • skill.md:83-98
  • commands.md:3-28
  • tools.md:43-48

Vulnerability Type: Missing authentication and action-level authorization for chat-driven operations
Risk Level: High

Relevant Code Snippets:

skill.md:83-98

markdown
### Chat-Driven Execution

Users can execute store tasks by sending messages through:

* WhatsApp
* Slack
* Telegram
* Web chat

Examples:

"Increase price of hoodie by 10%"
"Pause Meta ad set with lowest ROAS"
"Write blog about summer fashion trends"
"Check inventory of product SKU-445"

commands.md:3-28

markdown
Users can control the store via natural language.

Examples:

Increase price of SKU-444 by 5%

Check stock of black hoodie

Pause Meta ad set with lowest ROAS

Generate blog about winter fashion

Analyze competitor nike.com

Create discount campaign for summer sale

Show today's store performance

---

## Command Processing

1. Detect user intent
2. Map to appropriate tool
3. Execute action
4. Return summary

tools.md:43-48

markdown
## Messaging Automation

* read_whatsapp_message()
* send_whatsapp_reply()

Commands received through chat must be converted into actionable tasks.

Technical Analysis

The Skill instructs the agent to accept natural-language commands from WhatsApp, Slack, Telegram, and web chat, map them to tools, and execute them. The available operations include changing prices and inventory, publishing content, pausing ad sets, and modifying advertising budgets.

No documented control requires the agent to:

  • Authenticate the individual sender.
  • Verify that the sender belongs to the relevant store or tenant.
  • Check role-based or action-level permissions.
  • Restrict users to read-only or narrowly scoped operations.
  • Protect against replayed messages.
  • Bind approvals to a specific user, action, resource, and value.

...[truncated 2180 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require cryptographically verified identity for every messaging channel, including webhook-signature validation and secure account linking.
  2. Bind each authenticated identity to one explicit store or tenant and reject commands when that binding is absent or ambiguous.
  3. Implement role-based and action-level authorization. Separate read-only analytics access from inventory, pricing, publishing, and advertising permissions.
  4. Use least-privilege integration tokens with separate credentials and scopes for each tenant and operational domain.
  5. Require explicit, authenticated owner approval for every state-changing operation. The approval should identify the exact resource, proposed value, tenant, requester, and expiration time.
  6. Do not treat quoted, forwarded, generated, or third-party message content as executable authorization.
  7. Add replay protection using timestamps, nonces, message identifiers, and short approval-expiration periods.
  8. Apply strict parameter validation and policy limits, including maximum price changes, inventory bounds, budget ceilings, and resource allowlists.
  9. Record the authenticated requester, authorization decision, original command, resolved tool call, previous value, resulting value, and platform response in tamper-resistant audit logs.
  10. Provide immediate revocation, rollback, and incident-response controls for compromised messaging identities or integration tokens.

T09 · Insecure Skill Coding Practices

Warning
Location
workflows.md:22
Finding

Contradictory Approval Rules Permit Automated Advertising Mutations

Content
View full analysis

Vulnerability Details

File Locations:

  • skill.md:102
  • commands.md:30
  • workflows.md:22-27

Vulnerability Type: Inconsistent confirmation policy for financially sensitive actions
Risk Level: Medium

Relevant Code Snippets:

skill.md:102

markdown
1. Always confirm before destructive actions.

commands.md:30

markdown
Always verify before critical actions like deleting products or pausing campaigns.

workflows.md:22-27

markdown
## Ad Optimization

Every 24 hours:

1. Pull campaign metrics
2. Detect low ROAS campaigns
3. Pause underperforming ads
4. Scale winning campaigns

Technical Analysis

The general behavior and command-processing rules require confirmation or verification before destructive and critical actions, explicitly identifying campaign pausing as a critical action. However, the scheduled advertising workflow directly instructs the agent to pause underperforming ads and scale winning campaigns every 24 hours.

The documentation provides no rule establishing which instruction takes precedence. It also defines no mandatory approval state, spending ceiling, metric-freshness requirement, minimum sample size, confidence threshold, idempotency control, or rollback procedure. An implementation following the workflow literally may therefore mutate campaign state or budget without the confirmation required elsewhere.

This inconsistency is security-relevant because advertising changes have direct financial consequences. Inaccurate, stale, incomplete, or manipulated analytics may cause the automation to classify campaigns incorrectly and execute harmful actions.

Attack Path

  1. The scheduled advertising workflow retrieves campaign metrics.
  2. Metrics are stale, incomplete, incorrectly attributed, or manipulated through traffic or conversion activity.
  3. The agent classifies a legitimate campaign as underperforming or classifies a campaign as ...[truncated 1302 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace automatic mutation steps with explicit recommendations pending authenticated owner approval:
    • Recommend pausing underperforming ads.
    • Recommend a bounded budget increase for winning campaigns.
  2. Define a single authoritative policy stating that scheduled workflows cannot bypass confirmation requirements.
  3. Require approval for the exact campaign, action, current value, proposed value, evidence, requester, and expiration time.
  4. Enforce hard budget ceilings, maximum percentage changes, daily aggregate limits, and account-level spending controls outside the language model.
  5. Validate metric freshness, attribution windows, sample size, statistical confidence, and data completeness before issuing a recommendation.
  6. Use a dry-run mode that shows intended changes and estimated impact before execution.
  7. Add idempotency keys and cooldown periods to prevent repeated scaling or pausing during recurring runs.
  8. Preserve previous campaign state and provide tested rollback procedures.
  9. Generate immutable audit logs containing the metrics, decision criteria, approval, API request, and resulting campaign state.
  10. Alert the owner immediately after any approved campaign mutation and stop further automation when anomalous spending or performance is detected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill exposes broad natural-language control over sensitive ecommerce operations such as pricing, ad campaign management, discounts, and competitor analysis without clearly constraining authorized actions, approved targets, or disambiguation rules. In an ecommerce operations context, ambiguous command interpretation can directly trigger financially or operationally harmful actions, especially because only some 'critical actions' are called out for verification while other impactful changes are not.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and command guidance do not warn users that natural-language requests may change live store settings, marketing campaigns, pricing, or published content. Because this is an AI ecommerce operations manager, missing warnings and safety guardrails make accidental misuse more dangerous: users may issue casual commands that have real business consequences without understanding the scope or need for confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly allows chat-driven execution of operational actions such as price changes, ad pausing, blog publishing, and inventory checks across multiple commerce and advertising platforms. Even though it says to confirm before destructive actions, it does not define authentication, authorization, channel trust, approval controls, or safeguards against prompt injection, impersonation, or accidental execution, making unauthorized or manipulated business actions plausible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This skill exposes multiple externally impactful and destructive capabilities such as ad budget changes, adset pausing, inventory updates, content publishing, competitor scraping, and automated WhatsApp replies, but provides no authorization checks, human-review requirements, scope limits, or safety guidance. The instruction that chat commands must be converted into actionable tasks increases the risk of prompt injection, accidental execution, or unauthorized business-impacting actions directly from natural-language input.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This workflow authorizes pausing underperforming ads and scaling winning campaigns without any stated confirmation step, guardrail, spend limit, or warning that it modifies live campaigns. In an ecommerce operations skill, that can cause unintended financial loss, business disruption, or unauthorized changes if the agent acts automatically or on weak signals.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The competitor monitoring workflow explicitly includes scraping competitor stores but provides no warning or constraint around terms of service, robots restrictions, rate limits, or privacy/legal considerations. In this business context, that omission can lead users or downstream agents to perform non-compliant collection activity that creates legal, contractual, or reputational risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase "If SEO opportunity detected" is vague because it does not define what qualifies as an SEO opportunity or who/what performs the detection. This could cause the workflow to activate under inconsistent or overly broad conditions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file discusses API tokens and storing integration tokens, which affects sensitive credentials. Under the markdown-specific warning criterion, the description should warn users that the skill will access and retain authentication material and may interact with third-party services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.