Back to skill

Security audit

shopify library & shopify spy tool

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PPSPY Shopify research integration, with the main risk being trust in a globally installed third-party npm MCP server that receives the PPSPY API key.

Install only if you trust PPSPY and the npm package ppspy-mcp-server@1.0.1. Use a revocable PPSPY API key, monitor credit/billing usage, and prefer an isolated environment if global npm installs are a concern.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Globally Installed Third-Party Dependency Receives an API Credential

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12–25
Vulnerability Type: Third-party dependency and supply-chain exposure
Risk Level: Medium

Complete Code Snippet:

yaml
  install:
    command: npm
    args:
      - install
      - -g
      - "ppspy-mcp-server@1.0.1"
  primaryEnv: PPSPY_API_KEY
  emoji: "🔍"
  homepage: https://www.ppspy.com
  mcpServers:
    ppspy:
      command: ppspy-mcp-server
      env:
        PPSPY_API_KEY: "{{PPSPY_API_KEY}}"

Technical Analysis

The Skill installs ppspy-mcp-server@1.0.1 globally from the npm registry and then executes the installed binary with PPSPY_API_KEY in its environment. The dependency's source code is not included in the audited project, and the configuration does not specify an expected package integrity hash or another mechanism for verifying the downloaded artifact.

Pinning the package version limits unintentional version changes but does not independently authenticate the artifact. npm installation can also execute package lifecycle scripts. Consequently, a compromised package release, registry account, or package-distribution path could execute code during installation or when the MCP server starts.

The global -g installation increases the dependency's system-wide footprint compared with a project-local installation. There is no direct evidence in the reviewed file that ppspy-mcp-server@1.0.1 is malicious; the vulnerability is the unverified trust placed in an externally distributed executable that is subsequently given a sensitive credential.

Attack Path

  1. An attacker compromises the relevant npm publisher account, registry artifact, or another part of the package distribution chain.
  2. The victim activates the Skill, causing npm install -g ppspy-mcp-server@1.0.1 to retrieve and install the affected package.
  3. Malicious npm lifecycle code may execute during installation under the privileges of ...[truncated 1098 chars]
Remediation
View remediation

Remediation Suggestions

  1. Avoid global installation. Install the dependency in a project-local, isolated environment with minimal filesystem and network permissions.
  2. Vendor and review the MCP server source, or obtain it from a trusted, auditable source before execution.
  3. Use a lockfile containing npm integrity metadata and validate the expected artifact hash before installation.
  4. Disable npm lifecycle scripts during installation with --ignore-scripts when the package supports operation without them.
  5. Run the MCP server in a sandbox or container with access only to the resources required for PPSPY queries.
  6. Supply a narrowly scoped, revocable API key and document credential rotation and revocation procedures.
  7. Monitor API usage and billing for unexpected requests or credit consumption.
  8. Review the exact published contents and lifecycle scripts of ppspy-mcp-server@1.0.1 before approving deployment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: shopify-library
description: Search Shopify stores and products with PPSPY. Use this skill as a general Shopify library and Shopify spy tool for store, product, theme, and category research.
version: 1.0.0
metadata:
  openclaw:
    requires:
      env:
        - PPSPY_API_KEY
      bins:
        - npm
    install:
      command: npm
      args:
        - install
        - -g
        - "ppspy-mcp-server@1.0.1"
    primaryEnv: PPSPY_API_KEY
    emoji: "🔍"
    homepage: https://www.ppspy.com
    mcpServers:
      ppspy:
        command: ppspy-mcp-server
        env:
          PPSPY_API_KEY: "{{PPSPY_API_KEY}}"
---

# Shopify Library

Search Shopify stores, produ

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
## Setup

1. Visit the official website at [ppspy.com](https://www.ppspy.com/) to view real-time dashboard data and product UI.
2. Visit the direct API site at [api.ppspy.com](https://api.ppspy.com/) to get your API key and manage billing/recharge.
3. Set the environment variable: `PPSPY_API_KEY`

## Available Tools (9 total)

Static analysis

No suspicious patterns detected.