T09 · Insecure Skill Coding Practices
- Location
SKILL.md:29- Finding
API Key Solicitation and Exposure Through Chat and Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This looks like a real Shopify admin integration, but it handles powerful credentials and customer secrets in unsafe chat-based workflows while enabling live store changes.
Review before installing. Use only with a revocable, least-privilege key stored through a protected secret mechanism, not pasted into chat. Treat all mutations as live Shopify changes, confirm exact records and counts before execution or retry, avoid bulk actions unless scoped, and never provide customer passwords to the agent.
SKILL.md:29API Key Solicitation and Exposure Through Chat and Command-Line Arguments
queries/createCustomer.md:134Unnecessary Collection of Customer Passwords
Referenced artifact was not completely inspected
- **$QUERY**: Reference: queries/deleteProduct.md
Referenced artifact was not completely inspected
- **$QUERY**: Reference: queries/deleteCollection.md
Referenced artifact was not completely inspected
- **$QUERY**: Reference: queries/deleteCatalog.md
Referenced artifact was not completely inspected
- **$QUERY**: Reference: queries/deleteCodeDiscount.md
Referenced artifact was not completely inspected
- **$QUERY**: Reference: queries/deleteAutomaticDiscount.md
The README explicitly advertises full read/write access to Shopify Admin functionality, including destructive operations like deleting customers, orders, products, collections, catalogs, and discounts, but it does not prominently warn users that actions affect live production store data and may be irreversible. In an agent-executed skill, this increases the chance of unsafe or accidental high-impact actions because the user may not appreciate the operational risk from the top-level documentation alone.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- Save it to the `OPENCLAW_COMMERCE_API_KEY` environment variable
- **Test the connection** by calling the `/test` endpoint:
```bash
curl "$API_BASE/test" \
-H "X-OpenClaw-Commerce-Token: $OPENCLAW_COMMERCE_API_KEY"
```
- **If test succeeds (200 OK):** Confirm with "✅ API key saved successfully. You're now connected to your Shopify store."
The retry guidance tells the agent to resend GraphQL operations after errors, but this file concerns state-changing discount creation and activation mutations. If an initial request partially succeeded, timed out, or returned an ambiguous error, automatic retries can create duplicate discounts or activate promotions unexpectedly, directly affecting live store pricing and customer purchases.
The skill instructs an agent to create Shopify catalogs and discusses publication, markets, and storefront configuration, but it does not clearly warn that these actions modify live commerce settings and can change product availability or customer-facing storefront behavior. In a store-management skill, that omission increases the risk of unintended production changes, especially if an agent acts on ambiguous requests without explicit confirmation.
The skill documents bulk discount activation workflows without requiring an explicit confirmation step or warning about store-wide impact. In an agent setting, this can lead to accidental activation of many discounts at once, causing unintended promotions, pricing changes, and operational or revenue loss.
The bulk redemption/assignment guidance lacks a clear warning that customer-linked code operations may affect customer entitlements and involve customer identifiers. In practice, an agent could mass-assign or manipulate redemption-related records for the wrong customer set, creating privacy, fairness, and business logic issues.
The retry guidance tells the agent to resend queries after errors without distinguishing between safe reads and state-changing mutations. For create/activate/bulk operations, a blind retry can duplicate discounts, reactivate already-processed records, or partially repeat bulk changes after ambiguous failures, producing significant business impact.
The skill explicitly encourages retrying mutation requests after GraphQL errors while prioritizing task completion, but it does not require user confirmation or a warning that retries can create or modify live Shopify store data. In this context, the operation is a state-changing Admin API mutation, so repeated or corrected retries can unintentionally create duplicate collections, alter store organization, or perform unintended changes after ambiguous failures.
The skill instructs the agent to create customers and trigger customer-contact actions using personal data, but it does not require explicit confirmation, authorization, or prominent privacy/safety warnings before handling PII or sending customer-facing emails. In practice, this can lead to unintended collection, creation, or outreach using customer email, phone, address, and marketing-preference data without adequate user awareness or consent checks.
The documentation describes generating customer account activation URLs without clearly warning that these links are sensitive account-access artifacts. If an agent surfaces, stores, or mishandles such URLs, anyone with the link may be able to activate or gain access to the customer's account, creating a risk of account takeover and exposure of customer data.
The skill instructs an agent to generate order-creation operations that can directly modify Shopify store data and affect inventory, but it does not require an explicit confirmation or execution warning before performing state-changing actions. In an agentic context, this increases the risk of unintended order creation, stock changes, and operational disruption if user intent is ambiguous or the request is misinterpreted.
The skill describes email-sending options for invoices and receipts without requiring an explicit warning or confirmation that customer-facing communications may be sent. In practice, an agent could trigger unintended emails to customers, causing confusion, reputational harm, or accidental disclosure of draft or incorrect order details.
This skill instructs an agent to create, duplicate, and modify Shopify products, inventory-related fields, pricing, and bundles, but it does not prominently warn that these are state-changing operations against a merchant's live store data. In practice, an agent may proceed with insufficient confirmation or user awareness, leading to unintended catalog changes, pricing mistakes, inventory inconsistencies, or accidental publication-impacting edits.
The skill explicitly tells the agent to retry a failed GraphQL operation after re-reading documentation, but it does not require re-confirmation from the user before re-attempting destructive actions like collection deletion. In this skill, deletion is irreversible, so an automatic retry after an ambiguous failure, partial failure, or parameter correction could cause the agent to reissue a destructive mutation the user did not freshly approve.
This file is framed as 'Shopify Product & Options Deletion' but also adds instructions and templates for priceListDelete, which is a distinct pricing-management capability. That broadens the behavior of this skill artifact beyond the product-deletion function described in the file and is not clearly justified by the manifest context alone.
The file is explicitly scoped to generating Shopify automatic discount queries, but the agent instructions use an example workflow and user-facing fallback about product creation and product inventory settings. This is not merely incomplete documentation; it actively points the agent toward a different operation domain, contradicting the stated purpose of the file.
The query templates encourage retrieval of broad customer personal data, including email, phone, addresses, tags, order history, and spending details, without privacy guardrails, minimization guidance, or consent checks. In an agent setting, this increases the chance that an overbroad user request results in unnecessary exposure of sensitive customer information beyond what is needed for the task.
The file is intended to guide order and draft-order query generation, but the error-handling section tells the agent to revisit queries/createProduct.md after a GraphQL error. This cross-domain reference can misdirect the agent into using product-creation documentation and examples in an order-retrieval workflow, increasing the chance of malformed requests or unintended state-changing operations if the agent follows the wrong skill content during recovery.
The instruction 'When a user requests to fetch product data' is a high-level trigger description without explicit boundaries, exclusion conditions, or concrete invocation phrases. In a markdown skill file, this can cause the skill to match a wide range of ordinary product-related requests beyond the intended Shopify GraphQL query-generation context.
The skill explicitly guides generation and retry of queries for sensitive shop, billing, contact, and legal/business-entity data, but it does not require any privacy guardrails such as user confirmation, data minimization prompts, or warnings before exposing sensitive fields. In a merchant-facing assistant, this creates a real risk of over-collecting or disclosing confidential operational and legal information simply because the model is optimized to fulfill requests completely.
No suspicious patterns detected.