Back to skill

Security audit

Shopify Store Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This is an offline Shopify store-audit helper that generates checklist-style recommendations and does not access external services or sensitive local data.

Install if you want a template-based Shopify optimization checklist. Treat app recommendations and benchmark numbers as general guidance, verify pricing/current app details yourself, and do not expect it to inspect a live store or pull analytics because it explicitly runs without APIs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Phrases like 'optimization audit' or 'improvement recommendations' can overlap with many ordinary consulting-style requests unless tightly limited to Shopify store diagnostics. The trigger section does not provide negative examples or stricter scope boundaries to reduce ambiguous activation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file defines activation conditions as 'None' and says the skill is 'purely descriptive and always available.' That makes it unclear when the skill should activate versus not activate, increasing the chance of unintended invocation beyond clearly scoped Shopify audit requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code returns reports, checklists, and most recommendation text in Chinese, while also accepting English input in the demo. That creates a language-policy concern because users are not offered a locale choice and may receive output in a forced language without explicit opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest lists very generic trigger keywords such as "shopify" (L09), "seo" (L13), and "转化率" (L12) without any scope constraints or exclusion conditions. These terms are common in ordinary ecommerce discussions, so the skill could activate in contexts far broader than a specific Shopify store-optimization request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest sets the skill language to "zh-CN" while also including English trigger terms, but there is no indication that users can choose another language or that the locale restriction is explicitly justified. This creates a natural-language policy concern because the skill appears to enforce a specific locale without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The test suite emphasizes Chinese-language behavior throughout and specifically checks only that English is handled 'gracefully' while requiring a report note about no-API behavior. This suggests the skill may primarily force or assume a Chinese locale without an explicit user choice or documented rationale, which can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.