T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Global Installation and Execution of an Unverified Third-Party npm Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently sets up a PPSPY-based Shopify sales monitor, but users should understand it installs and runs an external npm MCP server with their PPSPY API key.
Install this only if you trust PPSPY and the npm package ppspy-mcp-server. Use a limited PPSPY API key if possible, avoid installing as an administrator, and confirm group/task IDs before running delete operations because they may remove monitoring setup.
SKILL.md:8Global Installation and Execution of an Unverified Third-Party npm Package
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
name: shopify-store-monitor
description: Track Shopify store sales and monitor store performance using PPSPY sales monitoring tools. Create monitoring tasks, inspect hourly and daily sales, and manage monitored stores.
version: 1.0.0
metadata:
openclaw:
requires:
env:
- PPSPY_API_KEY
bins:
- npm
install:
command: npm
args:
- install
- -g
- "ppspy-mcp-server@1.0.1"
primaryEnv: PPSPY_API_KEY
emoji: "🔍"
homepage: https://www.ppspy.com
mcpServers:
ppspy:
command: ppspy-mcp-server
env:
PPSPY_API_KEY: "{{PPSPY_API_KEY}}"
---
# Shopify Store Monitor
Track Shopify store sales, m
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Setup
1. Visit the official website at [ppspy.com](https://www.ppspy.com/) to view real-time dashboard data and product UI.
2. Visit the direct API site at [api.ppspy.com](https://api.ppspy.com/) to get your API key and manage billing/recharge.
3. Set the environment variable: `PPSPY_API_KEY`
## Available Tools (12 total)
This markdown file advertises destructive operations such as deleting groups and deleting stopped tasks, but provides no warning that these actions may remove monitoring configuration or be irreversible. For markdown files, safety-affecting behaviors should be disclosed when they could impact user data or system integrity.
No suspicious patterns detected.