Back to skill

Security audit

Openclaw Commerce Shopify

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real Shopify admin integration, but it handles powerful credentials and customer secrets in unsafe chat-based workflows while enabling live store changes.

Review before installing. Use only with a revocable, least-privilege key stored through a protected secret mechanism, not pasted into chat. Treat all mutations as live Shopify changes, confirm exact records and counts before execution or retry, avoid bulk actions unless scoped, and never provide customer passwords to the agent.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:29
Finding

API Key Solicitation and Exposure Through Chat and Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
queries/createCustomer.md:134
Finding

Unnecessary Collection of Customer Passwords

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (60)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
- **$QUERY**: Reference: queries/deleteProduct.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

md
- **$QUERY**: Reference: queries/deleteCollection.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
- **$QUERY**: Reference: queries/deleteCatalog.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
- **$QUERY**: Reference: queries/deleteCodeDiscount.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
- **$QUERY**: Reference: queries/deleteAutomaticDiscount.md

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly advertises full read/write access to Shopify Admin functionality, including destructive operations like deleting customers, orders, products, collections, catalogs, and discounts, but it does not prominently warn users that actions affect live production store data and may be irreversible. In an agent-executed skill, this increases the chance of unsafe or accidental high-impact actions because the user may not appreciate the operational risk from the top-level documentation alone.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
- Save it to the `OPENCLAW_COMMERCE_API_KEY` environment variable
   - **Test the connection** by calling the `/test` endpoint:
     ```bash
     curl "$API_BASE/test" \
       -H "X-OpenClaw-Commerce-Token: $OPENCLAW_COMMERCE_API_KEY"
     ```
   - **If test succeeds (200 OK):** Confirm with "✅ API key saved successfully. You're now connected to your Shopify store."

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The retry guidance tells the agent to resend GraphQL operations after errors, but this file concerns state-changing discount creation and activation mutations. If an initial request partially succeeded, timed out, or returned an ambiguous error, automatic retries can create duplicate discounts or activate promotions unexpectedly, directly affecting live store pricing and customer purchases.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs an agent to create Shopify catalogs and discusses publication, markets, and storefront configuration, but it does not clearly warn that these actions modify live commerce settings and can change product availability or customer-facing storefront behavior. In a store-management skill, that omission increases the risk of unintended production changes, especially if an agent acts on ambiguous requests without explicit confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill documents bulk discount activation workflows without requiring an explicit confirmation step or warning about store-wide impact. In an agent setting, this can lead to accidental activation of many discounts at once, causing unintended promotions, pricing changes, and operational or revenue loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The bulk redemption/assignment guidance lacks a clear warning that customer-linked code operations may affect customer entitlements and involve customer identifiers. In practice, an agent could mass-assign or manipulate redemption-related records for the wrong customer set, creating privacy, fairness, and business logic issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The retry guidance tells the agent to resend queries after errors without distinguishing between safe reads and state-changing mutations. For create/activate/bulk operations, a blind retry can duplicate discounts, reactivate already-processed records, or partially repeat bulk changes after ambiguous failures, producing significant business impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill explicitly encourages retrying mutation requests after GraphQL errors while prioritizing task completion, but it does not require user confirmation or a warning that retries can create or modify live Shopify store data. In this context, the operation is a state-changing Admin API mutation, so repeated or corrected retries can unintentionally create duplicate collections, alter store organization, or perform unintended changes after ambiguous failures.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to create customers and trigger customer-contact actions using personal data, but it does not require explicit confirmation, authorization, or prominent privacy/safety warnings before handling PII or sending customer-facing emails. In practice, this can lead to unintended collection, creation, or outreach using customer email, phone, address, and marketing-preference data without adequate user awareness or consent checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation describes generating customer account activation URLs without clearly warning that these links are sensitive account-access artifacts. If an agent surfaces, stores, or mishandles such URLs, anyone with the link may be able to activate or gain access to the customer's account, creating a risk of account takeover and exposure of customer data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs an agent to generate order-creation operations that can directly modify Shopify store data and affect inventory, but it does not require an explicit confirmation or execution warning before performing state-changing actions. In an agentic context, this increases the risk of unintended order creation, stock changes, and operational disruption if user intent is ambiguous or the request is misinterpreted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes email-sending options for invoices and receipts without requiring an explicit warning or confirmation that customer-facing communications may be sent. In practice, an agent could trigger unintended emails to customers, causing confusion, reputational harm, or accidental disclosure of draft or incorrect order details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill instructs an agent to create, duplicate, and modify Shopify products, inventory-related fields, pricing, and bundles, but it does not prominently warn that these are state-changing operations against a merchant's live store data. In practice, an agent may proceed with insufficient confirmation or user awareness, leading to unintended catalog changes, pricing mistakes, inventory inconsistencies, or accidental publication-impacting edits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly tells the agent to retry a failed GraphQL operation after re-reading documentation, but it does not require re-confirmation from the user before re-attempting destructive actions like collection deletion. In this skill, deletion is irreversible, so an automatic retry after an ambiguous failure, partial failure, or parameter correction could cause the agent to reissue a destructive mutation the user did not freshly approve.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

This file is framed as 'Shopify Product & Options Deletion' but also adds instructions and templates for priceListDelete, which is a distinct pricing-management capability. That broadens the behavior of this skill artifact beyond the product-deletion function described in the file and is not clearly justified by the manifest context alone.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file is explicitly scoped to generating Shopify automatic discount queries, but the agent instructions use an example workflow and user-facing fallback about product creation and product inventory settings. This is not merely incomplete documentation; it actively points the agent toward a different operation domain, contradicting the stated purpose of the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The query templates encourage retrieval of broad customer personal data, including email, phone, addresses, tags, order history, and spending details, without privacy guardrails, minimization guidance, or consent checks. In an agent setting, this increases the chance that an overbroad user request results in unnecessary exposure of sensitive customer information beyond what is needed for the task.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file is intended to guide order and draft-order query generation, but the error-handling section tells the agent to revisit queries/createProduct.md after a GraphQL error. This cross-domain reference can misdirect the agent into using product-creation documentation and examples in an order-retrieval workflow, increasing the chance of malformed requests or unintended state-changing operations if the agent follows the wrong skill content during recovery.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction 'When a user requests to fetch product data' is a high-level trigger description without explicit boundaries, exclusion conditions, or concrete invocation phrases. In a markdown skill file, this can cause the skill to match a wide range of ordinary product-related requests beyond the intended Shopify GraphQL query-generation context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly guides generation and retry of queries for sensitive shop, billing, contact, and legal/business-entity data, but it does not require any privacy guardrails such as user confirmation, data minimization prompts, or warnings before exposing sensitive fields. In a merchant-facing assistant, this creates a real risk of over-collecting or disclosing confidential operational and legal information simply because the model is optimized to fulfill requests completely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.