Back to skill

Security audit

Shopify Product SERP Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This is a Shopify product SEO skill with disclosed read/write abilities, bounded to previewed and approved product-field updates.

Install only for stores where you are comfortable granting Shopify product/file read and write access. Use public storefront mode for read-only audits, and in connected modes review the generated preview bundle carefully before allowing apply --execute, especially because it can change public product copy and image alt text.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
This methodology expands the skill from on-site Shopify product SERP optimization into blog ideation, community targeting, and off-page distribution guidance. That scope creep is dangerous because it can cause the agent to operate outside the user’s expected remit, generating recommendations for external promotion channels and quasi-link-building activities that are not aligned with the manifest and may create compliance, spam, or reputation risk.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The file requires live Google and Amazon evidence gathering during execution, which extends the skill beyond a Shopify audit/recommendation role into external data collection and competitive intelligence. This is risky because it changes the tool’s data-access and behavior model, potentially triggering unapproved browsing, third-party dependency, and leakage of analysis scope beyond what the skill advertises.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The methodology adds external community and outreach recommendation behavior, including Reddit, blogger, Facebook group, and outreach angles, which is outside the stated product-page search snippet optimization purpose. Even without direct automation, this can steer the agent toward manipulative or reputationally risky off-platform actions that users may not expect from a SERP metadata optimization skill.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The apply command can perform real Shopify Admin mutations whenever --execute is supplied, but there is no interactive confirmation, dry-run diff acknowledgement, or user-facing high-risk warning at execution time. In an agent or automation context, that makes accidental or prompt-induced destructive changes materially easier, especially because the skill holds write_products and write_files capability.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/shopify-dev-dashboard-auth.mjs:4

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/onboarding-guide.md:45