Back to skill

Security audit

Ecommerce Manager Claw

Security checks for vulnerabilities and agentic risk

Overview

The skill is meant for ecommerce administration, but it asks users to share powerful store credentials in chat and can change live store data with weak scoping and safety controls.

Review before installing. Use this only with stores you control, prefer read-only or narrowly scoped tokens, avoid pasting admin secrets or refresh tokens into normal chat, test on a sandbox store first, require explicit confirmation before any write action, and revoke or rotate any temporary credentials after use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:19
Finding

Administrative Credentials Are Collected Through the Conversation Without Secure Secret Handling

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19-39 and 83
Vulnerability Type: Plaintext sensitive credential handling
Risk Level: High

Vulnerable Code Snippet

markdown
## Step 1 — Identify the Platform & Collect Credentials

Start by warmly asking which platform the user is on if they haven't said.
Then ask for the credentials needed (listed below per platform). Reassure them:
> "These are only used for this session and are never stored anywhere."

### Credential requirements by platform

| Platform | What to ask for |
|---|---|
| **Shopify** | Store URL (e.g. `mystore.myshopify.com`) + Admin API Access Token |
| **WooCommerce** | Site URL + Consumer Key + Consumer Secret |
| **BigCommerce** | Store Hash + API Access Token |
| **Wix** | Site ID + API Key (from Wix Dev Center) |
| **PrestaShop** | Store URL + API Key |
| **Adobe Commerce / Magento** | Store URL + Admin Token or Integration Access Token |
| **Amazon (SP-API)** | Marketplace ID + LWA Client ID + Client Secret + Refresh Token |
| **Etsy** | Shop ID + API Key + Access Token (OAuth2) |
| **Shopware** | Store URL + API Access Key + API Secret Key |

The only additional credential-handling control appears at line 83:

markdown
- Never expose raw credentials in your responses

Technical Analysis

The Skill explicitly directs users to submit high-value ecommerce administrator credentials through the conversational interface. These include administrative access tokens, API secrets, OAuth refresh tokens, and client secrets.

No secure secret-entry mechanism, secret-manager integration, tokenization process, transcript-redaction procedure, logging control, or enforced secret lifetime is defined. The instruction not to expose credentials in responses only reduces accidental output disclosure; it does not prevent secrets from entering conversation history, Agent context, tool-call records, telemetry, or other retained execution data.

The statement that credent ...[truncated 1454 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prohibit users from pasting raw credentials into ordinary conversation messages.
  2. Integrate a dedicated masked secret-input mechanism or external secret manager.
  3. Pass opaque secret references to tools rather than including credential values in Agent-visible context.
  4. Define and enforce automatic secret expiration and deletion after the requested operation.
  5. Redact authorization headers, access tokens, API keys, client secrets, and refresh tokens from all logs and tool traces.
  6. Replace the unsupported “never stored anywhere” assurance with an accurate explanation of retention and processing boundaries.
  7. Prefer short-lived OAuth access tokens over persistent administrator tokens or refresh tokens.
  8. Tell users how to revoke and rotate credentials immediately after use.
  9. Add automated output and logging filters for known credential formats.
  10. Separate read-only and write-enabled credential workflows so high-risk credentials are requested only when necessary.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/credential-guides.md:8
Finding

Credential Setup Guidance Encourages Excessive API Privileges

Content
View full analysis

Vulnerability Details

File Location: references/credential-guides.md, lines 8-18, 23-30, 35-41, 46-52, 57-63, 68-74, 91-96, and 101-107
Vulnerability Type: Violation of least privilege
Risk Level: High

Vulnerable Code Snippets

Shopify guidance presents broad read and write access across multiple resource classes:

markdown
## Shopify

1. Log in to your Shopify admin panel
2. Go to **Settings** → **Apps and sales channels** → **Develop apps**
3. Click **Create an app**, give it a name (e.g. "Claude Assistant")
4. Under **Configuration**, enable the Admin API scopes you need:
   - `read_products`, `write_products` — for product management
   - `read_orders`, `write_orders` — for order management
   - `read_inventory`, `write_inventory` — for inventory
   - `read_customers`, `write_customers` — for customers
5. Click **Install app**, then copy the **Admin API access token**

WooCommerce guidance recommends unrestricted read/write permissions:

markdown
## WooCommerce

1. Log in to your WordPress admin dashboard
2. Go to **WooCommerce** → **Settings** → **Advanced** → **REST API**
3. Click **Add key**
4. Set Description (e.g. "Claude"), User, and Permissions to **Read/Write**
5. Click **Generate API key**

PrestaShop guidance lists every operation class:

markdown
## PrestaShop

1. Log in to your PrestaShop back office
2. Go to **Advanced Parameters** → **Web Service**
3. Click **Add new webservice key**
4. Set permissions (GET, PUT, POST, DELETE) for resources you need
5. Copy the generated **API Key**

Etsy guidance similarly combines read and write access:

markdown
## Etsy

1. Go to [etsy.com/developers](https://www.etsy.com/developers)
2. Click **Create a New App**
3. Fill in app details, select **Read** and **Write** scopes
4. Follow the OAuth2 flow to get an **Access Token**

Shopware guidance explicitly suggests an administrator role:

markdown
## Shopware

1. Log in to your Shopware Admin
2. Go to **Set
...[truncated 2690 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create a platform-specific scope matrix mapping each supported operation to its exact required permissions.
  2. Default all integrations to read-only access.
  3. Request write privileges only when the user authorizes a specific mutation that requires them.
  4. Never recommend an Administrator role when custom permissions can support the requested task.
  5. Separate credentials by resource and capability where supported, such as inventory-read, product-write, and order-fulfillment credentials.
  6. Exclude delete, customer-write, and order-cancellation privileges unless the user explicitly requests those operations.
  7. Prefer short-lived, narrowly scoped OAuth tokens and just-in-time authorization.
  8. Add preflight checks that reject credentials whose scopes materially exceed the requested operation where platforms expose scope metadata.
  9. Instruct users to revoke temporary integrations after completion.
  10. Document concrete least-privilege examples for each platform and each supported action.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (24)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger is extremely broad, including casual mentions of a store or shop and directing the agent to 'always use this skill' for ecommerce-related interactions. That increases the chance the skill will activate without clear user intent and begin soliciting or using sensitive backend credentials in contexts where the user did not mean to perform privileged account actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to ask for highly sensitive API credentials, including admin tokens, client secrets, and refresh tokens, but does not provide a strong warning about account takeover risk, least-privilege scoping, or safer alternatives. In this context, these credentials can grant broad read/write control over storefronts, orders, products, and customer data, making credential solicitation especially dangerous.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

This line instructs collection of a Shopify Admin API Access Token, which is a privileged secret that can enable direct administrative actions against the store. Requesting such credentials in conversational context materially increases the risk of exposure, replay, misuse, or accidental retention in logs or transcripts.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
| Platform | What to ask for |
|---|---|
| **Shopify** | Store URL (e.g. `mystore.myshopify.com`) + Admin API Access Token |
| **WooCommerce** | Site URL + Consumer Key + Consumer Secret |
| **BigCommerce** | Store Hash + API Access Token |
| **Wix** | Site ID + API Key (from Wix Dev Center) |

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This section asks for API keys and admin or integration access tokens for multiple platforms, all of which are high-value credentials capable of granting backend access. Consolidating such secret collection in a generic skill without strong handling guarantees magnifies the likelihood of credential compromise and unauthorized store manipulation.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
|---|---|
| **Shopify** | Store URL (e.g. `mystore.myshopify.com`) + Admin API Access Token |
| **WooCommerce** | Site URL + Consumer Key + Consumer Secret |
| **BigCommerce** | Store Hash + API Access Token |
| **Wix** | Site ID + API Key (from Wix Dev Center) |
| **PrestaShop** | Store URL + API Key |
| **Adobe Commerce / Magento** | Store URL + Admin Token or Integration Access Token |

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

This line requests Amazon SP-API client credentials, client secret, refresh token, and Etsy access-token material, which are especially sensitive because they can enable durable authenticated access and token refresh. Exposure of these values can lead to sustained unauthorized access to marketplace operations and associated business data.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
| **BigCommerce** | Store Hash + API Access Token |
| **Wix** | Site ID + API Key (from Wix Dev Center) |
| **PrestaShop** | Store URL + API Key |
| **Adobe Commerce / Magento** | Store URL + Admin Token or Integration Access Token |
| **Amazon (SP-API)** | Marketplace ID + LWA Client ID + Client Secret + Refresh Token |
| **Etsy** | Shop ID + API Key + Access Token (OAuth2) |
| **Shopware** | Store URL + API Access Key + API Secret Key |

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This line requests additional API access and secret keys for Shopware and nearby entries include other privileged credential types, continuing a pattern of broad secret harvesting. Because the skill is designed for real-time administrative operations across many storefronts, compromise of these secrets can directly affect orders, products, inventory, and customer information.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
| **PrestaShop** | Store URL + API Key |
| **Adobe Commerce / Magento** | Store URL + Admin Token or Integration Access Token |
| **Amazon (SP-API)** | Marketplace ID + LWA Client ID + Client Secret + Refresh Token |
| **Etsy** | Shop ID + API Key + Access Token (OAuth2) |
| **Shopware** | Store URL + API Access Key + API Secret Key |

For non-technical users, guide them step-by-step on where to find these.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/amazon-shopware.md (reported line 7)May include surrounding context.

  • EU: https://sellingpartnerapi-eu.amazon.com
  • FE: https://sellingpartnerapi-fe.amazon.com

Auth: OAuth2 LWA (Login with Amazon). Exchange refresh token for access token first:

POST https://api.amazon.com/auth/o2/token

json

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

This content explicitly tells the user to copy a Shopify Admin API access token, which is a high-value secret that can enable reading or modifying products, orders, inventory, and customer data. In an agent skill whose purpose is to manage ecommerce backends, prompting users toward obtaining and potentially supplying such tokens is more dangerous than generic documentation because the surrounding workflow likely encourages immediate use of those credentials.

Content

Scanner excerpt · references/credential-guides.md (reported line 18)May include surrounding context.

md
- `read_orders`, `write_orders` — for order management
   - `read_inventory`, `write_inventory` — for inventory
   - `read_customers`, `write_customers` — for customers
5. Click **Install app**, then copy the **Admin API access token**
6. Your store URL is `yourstore.myshopify.com`

---

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The BigCommerce section instructs the user to copy an access token without warning about secure handling, least privilege, or revocation. Because such a token can enable privileged API operations against a live store, exposure could lead to unauthorized order, product, inventory, or customer-data access and modification.

Content

Scanner excerpt · references/credential-guides.md (reported line 41)May include surrounding context.

md
2. Go to **Settings** → **API** → **API Accounts**
3. Click **Create API Account** → **Create V2/V3 API Token**
4. Set a name and select permissions for Products, Orders, Customers, Inventory
5. Click **Save** and copy the **Access Token**
6. Your Store Hash is in the URL: `store-XXXXXXX.mybigcommerce.com`

---

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The Magento/Adobe Commerce instructions direct the user to obtain and copy an access token, but provide no guardrails about safe storage or transmission. In this skill context, that omission is significant because the token may provide broad administrative API access to a production ecommerce environment, making accidental disclosure highly impactful.

Content

Scanner excerpt · references/credential-guides.md (reported line 74)May include surrounding context.

md
2. Go to **System** → **Integrations** → **Add New Integration**
3. Fill in the name, then go to **API** tab and select resource access
4. Click **Save** → **Activate** → **Allow**
5. Copy the **Access Token**
6. Your store URL is your Magento website address

---

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The Etsy section tells the user to complete OAuth and obtain an access token but does not state that the token is sensitive or how it should be handled safely. In a skill designed to operate on store backends, this can normalize sharing live bearer tokens that may permit unauthorized access to shop data and actions if intercepted or pasted into the wrong place.

Content

Scanner excerpt · references/credential-guides.md (reported line 96)May include surrounding context.

md
1. Go to [etsy.com/developers](https://www.etsy.com/developers)
2. Click **Create a New App**
3. Fill in app details, select **Read** and **Write** scopes
4. Follow the OAuth2 flow to get an **Access Token**
5. Your **Shop ID** is found in your Etsy shop URL

---

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly tells users that credentials are 'never stored anywhere,' but the document provides no technical control, retention boundary, or operational guarantee to enforce that claim. This creates a misleading privacy assurance around highly sensitive secrets and can cause users to disclose admin tokens under false assumptions about handling and persistence.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/amazon-shopware.md (reported line 9)May include surrounding context.

Auth: OAuth2 LWA (Login with Amazon). Exchange refresh token for access token first:

POST https://api.amazon.com/auth/o2/token

json
{
  "grant_type": "refresh_token",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This reference documents multiple live state-changing operations, including shipment confirmation, product creation and updates, order status transitions, customer updates, and product deletion, without any warning, approval requirement, or guidance to distinguish read-only from mutating actions. In an ecommerce-management skill, this is dangerous because an agent may execute these actions against production stores and marketplaces, causing inventory corruption, accidental fulfillment, cancellations, or deletion of live catalog data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/bigcommerce.md (reported line 3)May include surrounding context.

md
# BigCommerce API Reference

Base URL: `https://api.bigcommerce.com/stores/{store_hash}/v3/`
Auth header: `X-Auth-Token: {access_token}`, `Content-Type: application/json`

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This reference documents multiple state-changing and destructive ecommerce API operations, including inventory updates, order status changes, customer updates, product creation, and product deletion, without any warning about irreversible or business-impacting effects. In a skill explicitly intended to manage live store backends in real time, this increases the risk of accidental or unauthorized modifications to products, orders, inventory, and customer data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users how to obtain powerful API credentials but does not warn that these secrets grant direct access to store data and actions, nor that they should never be pasted into general chat or shared insecurely. In the context of an ecommerce-management skill that may prompt users for backend access, this omission materially increases the risk of credential disclosure and subsequent account compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This reference file documents multiple state-changing and destructive Etsy API operations including create, update, delete, shipping confirmation, and inventory updates, but provides no caution that these actions modify live store data. In the context of an agent skill explicitly designed to manage ecommerce backends in real time, this omission increases the chance that an agent or operator will perform irreversible or business-impacting actions without confirmation, dry-run support, or awareness of consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This reference documents multiple state-changing and destructive Magento operations, including product creation, updates, deletion, stock modification, order shipment/invoicing/cancellation, and customer updates, without any warning that these actions mutate live store data. In the context of an agent skill explicitly intended to manage ecommerce backends in real time and to be used broadly whenever a user mentions their shop, this increases the risk of unintended or socially engineered actions that damage inventory, orders, products, or customer records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file documents product update operations and later stock and order-status changes, but it does not warn that these requests alter live commerce data and may be irreversible or customer-visible. Under the markdown-specific warning criteria, descriptions of behaviors affecting user data or system integrity should disclose those risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This reference documents multiple state-changing Shopify mutations, including inventory changes, fulfillment creation, customer updates, product creation/updates, and product deletion, without requiring confirmation prompts, warning language, or guardrails around irreversible actions. In the context of an ecommerce-management skill that is supposed to act on live store backends, this can lead an agent to perform destructive or financially significant operations from ambiguous or casual user requests, causing inventory corruption, accidental fulfillment, data loss, or customer-impacting changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This reference file documents live ecommerce API operations that can modify products, inventory, and order fulfillment status, as well as query customer contact data, without any guardrails or warnings about requiring explicit user confirmation before write actions or handling sensitive customer data carefully. In the context of a skill explicitly designed to always manage store backends, this increases the risk that an agent could perform unauthorized or accidental state-changing operations or expose customer information based on ambiguous prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The reference explicitly documents state-changing and destructive WooCommerce actions such as updating stock, changing order status, editing customer records, creating products, and force-deleting products, but it provides no guardrails about confirmation, authorization scope, or irreversible effects. In the context of an ecommerce-management skill that is meant to act on live store backends, this increases the risk of accidental or unauthorized business-impacting actions, including inventory corruption, order mishandling, customer data changes, and product deletion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file instructs use of HTTP Basic Auth with an API key as the username but provides no caution about secure storage, redaction, or avoiding exposure in logs and transcripts. In the context of an agent skill that actively manages ecommerce backends, missing credential-handling guidance increases the chance of accidental key disclosure and subsequent unauthorized store access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.