Back to skill

Security audit

Shopify Auto Invoicing & Inventory

Security checks for vulnerabilities and agentic risk

Overview

This skill is a review-first local Shopify reporting helper, but its CSV exports should be handled carefully because spreadsheet formula escaping is missing.

Install only if you are comfortable using it as a local, review-first helper for Shopify exports. Treat generated CSV files as untrusted business data: inspect inputs, avoid opening exports with formula execution enabled, and consider adding spreadsheet-safe escaping before using the scripts for customer-controlled order or product data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/invoice_export.py:55
Finding

CSV Formula Injection in Invoice Exports

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/stock_sync.py:83
Finding

CSV Formula Injection in Stock Reconciliation Exports

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/monthly_ops_report.py:57
Finding

CSV Formula Injection Through SKU Values in Monthly Reports

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/monthly_ops_report.py:51
Finding

Malformed Quantity Causes Monthly Report Generation to Fail

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The skill advertises broad Shopify workflow capabilities, but the described/bundled behavior appears limited to local file transformation and reporting helpers. This mismatch can mislead operators into trusting the skill to perform order detection, inventory reconciliation, or monthly reporting correctly when those controls may not actually exist, increasing the chance of incorrect financial or stock actions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.