Back to skill

Security audit

myskill

Security checks for vulnerabilities and agentic risk

Overview

This skill is for Shopify sales monitoring, but it tells the agent to create a recurring cron job while its safety documentation says there is no scheduling or persistence.

Review before installing. This skill may lead an agent to create a recurring cron job that keeps accessing Shopify data and sending reports, despite documentation claiming no scheduling. Only use it if you explicitly want recurring monitoring, can restrict the Shopify API key to read-only minimum scopes, can verify where email/Telegram reports go, and have a clear way to inspect and remove any scheduled task.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
SKILL.md:14
Finding

Persistent Cron Job Creation Contradicts the Documented Safety Boundary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:14 and README.md:6
Vulnerability Type: Scheduled-task persistence
Risk Level: High

Vulnerable Code Snippets

SKILL.md:14:

text
→ Agent: Fetches sales data → Sends report → Sets cron job

Contradictory security claim in README.md:6:

text
✅ **No persistence** - No cron/scheduling

Technical Analysis

The skill explicitly instructs the agent to create a cron job after fetching Shopify data and sending a report. A cron job survives the original skill invocation and can execute commands in later sessions, making this system persistence.

This behavior directly contradicts the README's claim that the skill performs no persistence or scheduling. The contradiction prevents users and reviewers from making an informed security decision before enabling the skill.

The package does not define the scheduled command, execution frequency, credential-storage method, report destination, removal procedure, or safeguards against embedding secrets in cron configuration. An agent implementing the instruction could therefore create an unattended task that repeatedly accesses Shopify data and transmits reports using the permissions available to the user or agent account.

Attack Path

  1. A user requests daily Shopify monitoring.
  2. The agent follows the workflow in SKILL.md.
  3. The user provides a Shopify API key as required by the skill.
  4. The agent fetches sales or inventory data and sends a report.
  5. The agent creates a cron job to repeat the workflow.
  6. The scheduled task persists beyond the initiating interaction and continues executing without a newly issued user request.
  7. If credentials are placed in the cron command, environment, or an insecure supporting file, they may be exposed to other local processes or users.
  8. The task can continue accessing and transmitting data until the cron entry is discovered and removed or its ...[truncated 841 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to create a cron job if persistence is not an intended and supported feature.
  2. If recurring scheduling is required, disclose it consistently in SKILL.md, README.md, and the package metadata.
  3. Require explicit, informed user confirmation immediately before creating any scheduled task. The confirmation should identify the command, frequency, data accessed, destination, and effective operating-system account.
  4. Use the narrowest possible Shopify API scopes and a dedicated credential limited to required read-only resources.
  5. Never place API keys, email credentials, Telegram tokens, or other secrets directly in a cron command or world-readable file. Use an appropriately protected secret store.
  6. Define and validate the exact scheduled command rather than allowing unconstrained command generation.
  7. Provide a clear command or automated mechanism for inspecting, disabling, and permanently removing the scheduled task.
  8. Record task creation and execution in an auditable log without recording secrets or sensitive Shopify data.
  9. Apply execution limits, destination allowlists, failure handling, and credential revocation procedures.
  10. Correct the contradictory statement in README.md:6 before distribution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrase "check sales" is broad enough to match ordinary user requests that may not be intended to invoke this specific skill. In an agent environment, that can cause unintended activation, leading to access of Shopify data or downstream actions such as reporting and notification setup without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description does not clearly warn that it may create persistent scheduled monitoring and send outbound Telegram/email notifications. That omission increases the risk of users unintentionally authorizing ongoing background actions, external data transmission, and repeated access to store analytics beyond what they expected from a one-time request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README advertises daily sales summaries via email but does not warn users that business data will be transmitted over email, which may expose sensitive sales or inventory information if mail delivery is insecure, misaddressed, or retained in mailboxes. The repeated safety-marketing claims and 'VirusTotal Clean' language do not mitigate this risk and may create false reassurance about operational data exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.