T09 · Insecure Skill Coding Practices
- Location
references/deployment.md:51- Finding
Shopify API Token Exposed Through Terminal Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This docs-only Shopify skill is coherent, but it needs review because some deployment steps can expose a write-capable token or run mutable/project-controlled commands.
Review this skill before installing if an agent may execute its deployment commands. Do not print `.env.local` token values; require explicit approval before any `theme push` to live or `theme publish`; prefer direct, reviewed Shopify CLI commands; and pin or preinstall npm tooling in a controlled environment.
references/deployment.md:51Shopify API Token Exposed Through Terminal Output
references/performance.md:181Unpinned Third-Party Packages May Be Downloaded and Executed
references/deployment.md:154Project-Controlled npm Lifecycle Scripts Can Execute Arbitrary Commands During Deployment
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Verify SHOPIFY_CLI_THEME_TOKEN is set in .env.local:
grep SHOPIFY_CLI_THEME_TOKEN .env.local
If missing or empty, the push will fail with 401 Unauthorized.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Verify SHOPIFY_CLI_THEME_TOKEN is set in .env.local:
grep SHOPIFY_CLI_THEME_TOKEN .env.local
If missing or empty, the push will fail with 401 Unauthorized.
The skill documents shopify theme publish --theme <THEME_ID> as a normal workflow step without a clear inline warning that this action makes the selected theme live immediately. In an agent-executed context, presenting a production-impacting command without strong guardrails can cause accidental publication of unfinished or unsafe changes to a storefront.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
No suspicious patterns detected.