Back to skill

Security audit

Ned - Shopify Profit Analytics AI

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly coherent Ned analytics connector, but it should be reviewed because broad prompts can make an agent use your API key to pull sensitive business and customer analytics.

Install only if you intend your agent to query Ned for Shopify analytics and you trust Ned with that data. Use a scoped or revocable API key if available, avoid sharing the key in logs or chats, and consider requiring explicit confirmation before customer-level, product-margin, churn-risk, or ad-performance queries.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill invokes shell-based network access via curl and a bundled bash script, but it does not declare any tool restrictions or allowed tools in metadata. That increases the chance an agent can execute shell commands unexpectedly when the skill is auto-selected, expanding the attack surface and weakening least-privilege controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description contains very broad trigger phrases like profit, revenue, sales, customers, ad performance, and 'how is my store doing,' which overlap with many normal ecommerce conversations. In agent environments with automatic skill routing, this can cause over-invocation and unintended access to external services and sensitive analytics data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that it gives the agent direct access to profitability, customer segments, churn risk, and ad efficiency data stored in Ned, but it does not prominently warn that this information will be sent to and processed by a third-party service. Because the data includes sensitive business and potentially customer-related analytics, users may unknowingly authorize external disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This skill is explicitly designed to send authenticated requests to api.meetned.com using a bearer API key, which constitutes external transmission of sensitive store analytics. While expected for functionality, it is still a real security concern because compromise, misconfiguration, or unexpected invocation could disclose confidential business metrics and customer-related insights to a third party.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

API Base

text
https://api.meetned.com/api/v1

Auth: Authorization: Bearer $NED_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The example curl command demonstrates outbound authenticated transmission of profitability data to a third-party API. Although this is core functionality, embedding executable shell snippets increases the chance an agent will perform network actions automatically without sufficient guardrails or user awareness.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

bash
# Quick profit check
curl -s -H "Authorization: Bearer $NED_API_KEY" \
  "https://api.meetned.com/api/v1/profitability/summary?period=today"

# Top products by profit
curl -s -H "Authorization: Bearer $NED_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This example transmits product profitability data, which can reveal commercially sensitive margins, COGS, and performance information, to an external endpoint using a bearer token. The risk is amplified in an agent setting because shell-capable skills may execute these calls with minimal user visibility.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
# Top products by profit
curl -s -H "Authorization: Bearer $NED_API_KEY" \
  "https://api.meetned.com/api/v1/profitability/products?period=last_30_days"

# At-risk whale customers
curl -s -H "Authorization: Bearer $NED_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This request accesses customer-summary data including at-risk whales, which may involve sensitive customer segmentation and behavioral analytics, and sends/receives it through a third-party API. Customer-related analytics are more privacy-sensitive than aggregate metrics, so unintended or opaque transmission poses greater confidentiality and compliance risk.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

At-risk whale customers

curl -s -H "Authorization: Bearer $NED_API_KEY"
"https://api.meetned.com/api/v1/customers/summary?period=last_90_days" | jq '.data.at_risk_whales'

text

## Query Script

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ned-query.sh (reported line 15)May include surrounding context.

sh
exit 1
fi

URL="https://api.meetned.com/api/v1/${ENDPOINT}?period=${PERIOD}"

response=$(curl -s -w "\n%{http_code}" -H "Authorization: Bearer $NED_API_KEY" "$URL")
http_code=$(echo "$response" | tail -1)

Static analysis

No suspicious patterns detected.