Back to skill

Security audit

shopify product

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PPSPY Shopify product-research integration, with the main caution being its global npm-installed MCP server and API-key use.

Install this only if you trust PPSPY and the npm package ppspy-mcp-server@1.0.1. Use a revocable PPSPY API key with spending limits where possible, and prefer running the MCP server in an isolated or least-privilege environment if your agent has access to sensitive local files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unverified Global Installation of a Third-Party Executable

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–17
Vulnerability Type: Third-party dependency and supply-chain risk
Risk Level: Medium

yaml
    bins:
      - npm
    install:
      command: npm
      args:
        - install
        - -g
        - "ppspy-mcp-server@1.0.1"

Technical Analysis

The skill instructs npm to install ppspy-mcp-server@1.0.1 globally and subsequently relies on the resulting executable. Although the package version is pinned, the project provides neither the dependency source nor an integrity digest with which to authenticate the downloaded artifact.

Pinning a version prevents ordinary automatic upgrades, but it does not protect against compromise of the npm publisher account, package contents, package registry, configured registry endpoint, or distribution infrastructure. npm installation may also execute package lifecycle scripts. Such scripts can run during installation before the MCP server itself is invoked.

The global -g installation increases exposure by placing the package in a shared executable or module location rather than an isolated project environment. The reviewed project contains no lockfile, vendored source, checksum verification, lifecycle-script restriction, sandbox configuration, or other mechanism that permits the installed code to be independently verified.

Attack Path

  1. An attacker compromises the package publisher, npm distribution path, or the registry configured on the host.
  2. The attacker causes malicious content or lifecycle scripts to be served for the referenced package.
  3. Installation of the skill runs npm install -g ppspy-mcp-server@1.0.1.
  4. Malicious npm lifecycle code executes with the permissions of the user performing the installation, or the globally installed executable is replaced with attacker-controlled logic.
  5. When the MCP server is launched, the executable receives access to PPSPY_API_KEY throu ...[truncated 1008 chars]
Remediation
View remediation

Remediation Suggestions

  1. Avoid global installation. Install the server into a dedicated project directory or isolated container under an unprivileged service account.
  2. Vendor and audit the exact server source, or obtain it from a trusted internal registry after security review.
  3. Generate and retain a lockfile containing registry-resolved integrity metadata, and enforce reproducible installation with npm ci.
  4. Verify package provenance, publisher identity, signatures or attestations, and cryptographic artifact hashes before execution.
  5. Disable npm lifecycle scripts during installation with --ignore-scripts where compatible. If lifecycle scripts are required, review and explicitly allow them.
  6. Run the MCP server in a sandbox with minimal filesystem access, restricted process execution, and outbound network access limited to required PPSPY endpoints.
  7. Use a narrowly scoped, revocable API key with usage and billing limits. Do not expose unrelated environment variables to the server.
  8. Monitor dependency advisories, package ownership changes, integrity failures, API-key usage, and unexpected outbound connections.
  9. Document a trusted package-update process that requires source review and integrity verification before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: shopify-product
description: Search Shopify products and analyze winning items with PPSPY. Filter products by price, category, sales, and revenue, and inspect bestselling products by store.
version: 1.0.0
metadata:
  openclaw:
    requires:
      env:
        - PPSPY_API_KEY
      bins:
        - npm
    install:
      command: npm
      args:
        - install
        - -g
        - "ppspy-mcp-server@1.0.1"
    primaryEnv: PPSPY_API_KEY
    emoji: "🔍"
    homepage: https://www.ppspy.com
    mcpServers:
      ppspy:
        command: ppspy-mcp-server
        env:
          PPSPY_API_KEY: "{{PPSPY_API_KEY}}"
---

# Shopify Product

Search Shopify products, explore winning pro

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
## Setup

1. Visit the official website at [ppspy.com](https://www.ppspy.com/) to view real-time dashboard data and product UI.
2. Visit the direct API site at [api.ppspy.com](https://api.ppspy.com/) to get your API key and manage billing/recharge.
3. Set the environment variable: `PPSPY_API_KEY`

## Available Tools (3 total)

Static analysis

No suspicious patterns detected.