Back to skill

Security audit

Shopify Theme Pro

Security checks for vulnerabilities and agentic risk

Overview

This docs-only Shopify skill is coherent, but it needs review because some deployment steps can expose a write-capable token or run mutable/project-controlled commands.

Review this skill before installing if an agent may execute its deployment commands. Do not print `.env.local` token values; require explicit approval before any `theme push` to live or `theme publish`; prefer direct, reviewed Shopify CLI commands; and pin or preinstall npm tooling in a controlled environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/deployment.md:51
Finding

Shopify API Token Exposed Through Terminal Output

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/performance.md:181
Finding

Unpinned Third-Party Packages May Be Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/deployment.md:154
Finding

Project-Controlled npm Lifecycle Scripts Can Execute Arbitrary Commands During Deployment

Content
View full analysis
``` The rollback workflow executes the same npm script again: ```bash git checkout npm run theme:push ``` ### Technical Analysis A repository controls the contents of `package.json`. Running `npm run theme:push` executes the configured `theme:push` command and may also execute the corresponding `pretheme:push` and `posttheme:push` lifecycle scripts. The preceding `grep` command is not a reliable security validation. It does not parse the JSON, validate the complete command, detect shell metacharacters, or expose associated lifecycle hooks. A malicious or compromised theme repository can therefore attach arbitrary commands to an operation that appears to be a routine Shopify deployment. The deployment context may contain a Shopify token and other developer credentials. Executing unreviewed repository-defined scripts is not required to invoke Shopify CLI and exceeds the minimum privilege necessary for the declared deployment function. ### Attack Path 1. An attacker creates or compromises a Shopify theme repository. 2. The attacker defines a legitimate-looking `theme:push` script and adds malicious `pretheme:push`, `posttheme:push`, or shell commands. 3. A user or agent opens the repository and follows the documented deployment workflow. 4. `grep 'theme:push' package.json` displays only a partial or superficially benign match and does not identify all executable hooks. 5 ...[truncated 755 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deployment.md (reported line 54)May include surrounding context.

Verify SHOPIFY_CLI_THEME_TOKEN is set in .env.local:

bash
grep SHOPIFY_CLI_THEME_TOKEN .env.local

If missing or empty, the push will fail with 401 Unauthorized.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deployment.md (reported line 163)May include surrounding context.

Verify SHOPIFY_CLI_THEME_TOKEN is set in .env.local:

bash
grep SHOPIFY_CLI_THEME_TOKEN .env.local

If missing or empty, the push will fail with 401 Unauthorized.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents shopify theme publish --theme <THEME_ID> as a normal workflow step without a clear inline warning that this action makes the selected theme live immediately. In an agent-executed context, presenting a production-impacting command without strong guardrails can cause accidental publication of unfinished or unsafe changes to a storefront.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.