T09 · Insecure Skill Coding Practices
- Location
workflows/01-new-order-handler.json:23- Finding
Webhook authentication fails open when the signature or secret is absent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a legitimate Shopify automation skill, but it needs review because its public webhook can accept unauthenticated order data and the workflows handle customer PII and automated emails without enough safeguards.
Review before installing. Do not enable the public webhook or customer recovery emails until webhook verification fails closed using the raw request body, email content is escaped and recovery URLs are validated, and you have clear privacy, retention, access-control, opt-out, and deduplication rules for customer data.
workflows/01-new-order-handler.json:23Webhook authentication fails open when the signature or secret is absent
workflows/01-new-order-handler.json:176Unescaped Shopify and webhook data is interpolated into HTML email bodies
| Order | #{{ $json.order_number }} |
| Customer | {{ $json.customer_name }} |
| {{ $json.customer_email }} | |
| Total | {{ $json.currency }} {{ $json.total_price }} |
| Payment | {{ $json.financial_status }} |
| Items | {{ $json.items_summary }} |
| Shipping | {{ $json.shipping_address }} |
| Product | Variant | SKU | Stock | Price |
|---|---|---|---|---|
| ${item.product_title} | ${item.variant_title} | ${item.sku} | ${item.inventory_quantity} | ${item.price} |
We noticed you left some items in your cart:
Items: {{ $json.items }}
Total: {{ $json.currency }} {{ $json.total_price }}
Your cart is still saved! Complete your purchase here:
workflows/04-abandoned-cart-recovery.json:51Abandoned-cart recovery lacks deduplication and send-state tracking
We noticed you left some items in your cart:
Items: {{ $json.items }}
Total: {{ $json.currency }} {{ $json.total_price }}
Your cart is still saved! Complete your purchase here:
If you have any questions, just reply to this email.
", "o ...[truncated 1592 chars]Referenced artifact was not completely inspected
| 01 | `01-new-order-handler.json` | Webhook → parse order → log to Sheets → notify admin |
Referenced artifact was not completely inspected
| 04 | `04-abandoned-cart-recovery.json` | Scheduled → fetch abandoned carts → recovery email |
The skill handles and persists customer PII and commerce data in Google Sheets, and it automates outbound recovery emails to customers, but the description lacks clear privacy, consent, and compliance warnings. This is dangerous because operators may deploy it without understanding data-handling obligations, retention risks, or email-marketing/legal constraints, increasing the chance of privacy violations or abusive messaging.
The workflow persists customer PII and order data, including name, email, phone, shipping address, and purchase details, into Google Sheets. While this is likely intended for business operations, storing sensitive order data in a broad collaboration tool without any minimization, retention controls, or disclosure increases privacy and data exposure risk if the sheet is overshared, compromised, or retained indefinitely.
The workflow emails customer order details to an admin mailbox, including customer identity, contact information, purchased items, and shipping address. Email is commonly forwarded, retained, and less tightly controlled than transactional systems, so sending full order PII this way increases the chance of unauthorized disclosure or long-term uncontrolled storage.
The workflow uses Google Sheets OAuth credentials and reads a Shopify access token from environment variables for authenticated data access. The file does not include any explanatory text or warning that the workflow depends on and uses these credentials to access external services.
This JSON workflow makes authenticated HTTP requests to Shopify and writes returned order status data into Google Sheets on a recurring schedule. There is no visible warning, confirmation step, or descriptive note in the file explaining that external data will be fetched and persisted automatically.
This JSON workflow transmits product and stock information via email, including SKU and inventory quantities, but the file contains no user-facing warning, confirmation, or explanatory description about that outbound notification. For manifest/config-style workflow definitions, this is the only visible artifact here, so the email transmission lacks disclosure within the reviewed file.
This workflow automatically emails customers with their email address, item list, total price, and recovery link, which is a user-data-affecting outbound action. In this JSON file there is no confirmation step, user-facing notice, or explanatory description warning that customer data will be transmitted via email.
The file reads SHOPIFY_STORE_URL and SHOPIFY_ACCESS_TOKEN from environment variables and uses the access token in a request header to Shopify. There is no user-facing comment, warning, or description here that the skill depends on sensitive credentials and performs authenticated network access.
The workflow emails a daily sales report containing business data such as revenue, order counts, fulfillment, and top products to the address in SHOPIFY_ADMIN_EMAIL. In this JSON skill file there is no warning, confirmation, or explanatory note that collected Shopify data will be sent externally via email.
The manifest description highlights Google Sheets tracking and Shopify Admin API integration, but the documented behavior also includes sending admin notifications, abandoned-cart recovery emails, and daily sales report emails. Email delivery is a substantive operational capability, not just an incidental implementation detail, and it is not mentioned in the manifest summary line.
The HTTP request uses environment-derived store URL and access token values, including a sensitive Shopify access token. The file contains no user-facing comment, warning, or documentation indicating that the workflow reads credentials from the environment to access store checkout data.
No suspicious patterns detected.