Back to skill

Security audit

Best Shopify Stores

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PPSPY integration for finding Shopify stores, with the main risk being a third-party global npm install that receives an API key.

Before installing, verify that PPSPY and the npm package are the service you intend to use, use a limited or revocable PPSPY API key if available, monitor credit usage, and consider running the MCP server in an isolated environment because the global npm package code is not included in this artifact.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Global Installation and Execution of an Unverified Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8–23
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

yaml
bins:
  - npm
install:
  command: npm
  args:
    - install
    - -g
    - "ppspy-mcp-server@1.0.1"
primaryEnv: PPSPY_API_KEY
emoji: "🔍"
homepage: https://www.ppspy.com
mcpServers:
  ppspy:
    command: ppspy-mcp-server
    env:
      PPSPY_API_KEY: "{{PPSPY_API_KEY}}"

Technical Analysis

The Skill directs the host to install ppspy-mcp-server@1.0.1 globally from the npm registry and subsequently execute its binary with access to PPSPY_API_KEY.

Pinning the dependency to version 1.0.1 provides some reproducibility, but the configuration does not verify the package with a trusted integrity hash, lockfile, signature, or vendored source review. npm installation can also execute package lifecycle scripts. The global -g installation modifies the host-wide npm environment rather than an isolated project environment.

The package implementation is not included in the audited project, so its installation-time and runtime behavior cannot be verified from the supplied artifact. If the package version or its publication process is compromised, attacker-controlled code could execute under the privileges of the user running the Skill and receive the configured API credential.

Attack Path

  1. An attacker compromises the npm publisher account, registry delivery path, or package contents associated with ppspy-mcp-server@1.0.1.
  2. The Skill invokes npm install -g ppspy-mcp-server@1.0.1.
  3. Malicious package lifecycle scripts may execute during installation, or malicious logic may be installed in the ppspy-mcp-server binary.
  4. The host launches the installed binary as an MCP server.
  5. The process receives PPSPY_API_KEY through its environment.
  6. Attacker-controlled code can read or exfiltrate that credential and access files, network r ...[truncated 865 chars]
Remediation
View remediation

Remediation Suggestions

  1. Vendor and independently audit the MCP server source before deployment.
  2. Install the dependency into a dedicated, non-global project directory or isolated container instead of using npm install -g.
  3. Use a lockfile and verify the package archive against a trusted integrity hash or signed provenance.
  4. Disable npm lifecycle scripts during installation where the package does not require them, such as with --ignore-scripts.
  5. Run the MCP server under a dedicated, unprivileged operating-system account with restricted filesystem and network access.
  6. Pass only PPSPY_API_KEY to the process rather than inheriting the full parent environment.
  7. Use a narrowly scoped API key where supported, monitor its usage, and establish rotation and revocation procedures.
  8. Pin and validate the runtime executable path so an unrelated binary with the same name cannot be selected through PATH.
  9. Re-audit package source and transitive dependencies before upgrades or deployment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: best-shopify-stores
description: Discover the best Shopify stores with PPSPY by filtering stores by traffic, revenue, language, region, theme, and single-product characteristics.
version: 1.0.0
metadata:
  openclaw:
    requires:
      env:
        - PPSPY_API_KEY
      bins:
        - npm
    install:
      command: npm
      args:
        - install
        - -g
        - "ppspy-mcp-server@1.0.1"
    primaryEnv: PPSPY_API_KEY
    emoji: "🔍"
    homepage: https://www.ppspy.com
    mcpServers:
      ppspy:
        command: ppspy-mcp-server
        env:
          PPSPY_API_KEY: "{{PPSPY_API_KEY}}"
---

# Best Shopify Stores

Find and compare top Shopify stores us

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
## Setup

1. Visit the official website at [ppspy.com](https://www.ppspy.com/) to view real-time dashboard data and product UI.
2. Visit the direct API site at [api.ppspy.com](https://api.ppspy.com/) to get your API key and manage billing/recharge.
3. Set the environment variable: `PPSPY_API_KEY`

## Available Tools (6 total)

Static analysis

No suspicious patterns detected.