Back to skill

Security audit

magento-admin

Security checks for vulnerabilities and agentic risk

Overview

This is a clearly disclosed high-privilege Magento administration skill for store owners, with no evidence of hidden exfiltration or deceptive behavior.

Install only if you own and administer the Magento host, are comfortable granting the agent SSH, database, REST admin, and limited sudo authority, and will review high-impact commands such as refunds, admin-user creation, extension installs, database restore, service restarts, and raw SQL before allowing autonomous execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (96)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
below show this form.
- If `MAGENTO_CA_CERT` is **not set**, omit the `--cacert` option entirely and
  rely on the system CA store (correct for a public cert, e.g. Let's Encrypt).
- **Never** use `curl -k` / `--insecure` — that disables verification and is a
  genuine MITM risk, not just a scanner flag.

## SSH Patterns

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
below show this form.
- If `MAGENTO_CA_CERT` is **not set**, omit the `--cacert` option entirely and
  rely on the system CA store (correct for a public cert, e.g. Let's Encrypt).
- **Never** use `curl -k` / `--insecure` — that disables verification and is a
  genuine MITM risk, not just a scanner flag.

## SSH Patterns

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

bash
ssh -i MAGENTO_SSH_KEY -o StrictHostKeyChecking=yes MAGENTO_SSH_USER@MAGENTO_HOST "
echo '=== VERSION ===' && sudo -u MAGENTO_WEB_USER MAGENTO_PHP MAGENTO_WEB_ROOT/bin/magento --version 2>&1
echo '=== MODE ===' && sudo -u MAGENTO_WEB_USER MAGENTO_PHP MAGENTO_WEB_ROOT/bin/magento deploy:mode:show 2>&1
echo '=== SERVICES ===' && sudo systemctl is-active apache2 nginx mariadb mysql redis-server opensearch php8.3-fpm php8.4-fpm 2>/dev/null
echo '=== LOAD ===' && uptime

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

bash
ssh -i MAGENTO_SSH_KEY -o StrictHostKeyChecking=yes MAGENTO_SSH_USER@MAGENTO_HOST "
echo '=== VERSION ===' && sudo -u MAGENTO_WEB_USER MAGENTO_PHP MAGENTO_WEB_ROOT/bin/magento --version 2>&1
echo '=== MODE ===' && sudo -u MAGENTO_WEB_USER MAGENTO_PHP MAGENTO_WEB_ROOT/bin/magento deploy:mode:show 2>&1
echo '=== SERVICES ===' && sudo systemctl is-active apache2 nginx mariadb mysql redis-server opensearch php8.3-fpm php8.4-fpm 2>/dev/null
echo '=== LOAD ===' && uptime

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

bash
ssh -i MAGENTO_SSH_KEY -o StrictHostKeyChecking=yes MAGENTO_SSH_USER@MAGENTO_HOST "
echo '=== VERSION ===' && sudo -u MAGENTO_WEB_USER MAGENTO_PHP MAGENTO_WEB_ROOT/bin/magento --version 2>&1
echo '=== MODE ===' && sudo -u MAGENTO_WEB_USER MAGENTO_PHP MAGENTO_WEB_ROOT/bin/magento deploy:mode:show 2>&1
echo '=== SERVICES ===' && sudo systemctl is-active apache2 nginx mariadb mysql redis-server opensearch php8.3-fpm php8.4-fpm 2>/dev/null
echo '=== LOAD ===' && uptime

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

md
echo '=== LOAD ===' && uptime
echo '=== MEMORY ===' && free -h | grep Mem
echo '=== DISK ===' && df -h MAGENTO_WEB_ROOT | tail -1
echo '=== OPENSEARCH ===' && curl -s MAGENTO_OS_URL/_cluster/health 2>/dev/null | python3 -c 'import sys,json; d=json.load(sys.stdin); print(d[\"status\"])'
echo '=== REDIS ===' && redis-cli ping && redis-cli info keyspace
echo '=== CRON ===' && MYSQL_PWD=MAGENTO_DB_PASS mysql -uMAGENTO_DB_USER MAGENTO_DB_NAME -e 'SELECT status,COUNT(*) FROM cron_schedule WHERE scheduled_at>DATE_SUB(NOW(),INTERVAL 2 HOUR) GROUP BY status;' 2>&1
echo '=== ERRORS ===' && tail -3 MAGENTO_WEB_ROOT/var/log/exception.log 2>/dev/null | grep -c CRITICAL || echo 0

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 832)May include surrounding context.

md
echo '=== LOAD ===' && uptime
echo '=== MEMORY ===' && free -h | grep Mem
echo '=== DISK ===' && df -h MAGENTO_WEB_ROOT | tail -1
echo '=== OPENSEARCH ===' && curl -s MAGENTO_OS_URL/_cluster/health 2>/dev/null | python3 -c 'import sys,json; d=json.load(sys.stdin); print(d[\"status\"])'
echo '=== REDIS ===' && redis-cli ping && redis-cli info keyspace
echo '=== CRON ===' && MYSQL_PWD=MAGENTO_DB_PASS mysql -uMAGENTO_DB_USER MAGENTO_DB_NAME -e 'SELECT status,COUNT(*) FROM cron_schedule WHERE scheduled_at>DATE_SUB(NOW(),INTERVAL 2 HOUR) GROUP BY status;' 2>&1
echo '=== ERRORS ===' && tail -3 MAGENTO_WEB_ROOT/var/log/exception.log 2>/dev/null | grep -c CRITICAL || echo 0

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 612)May include surrounding context.

"MYSQL_PWD=MAGENTO_DB_PASS mysql -uMAGENTO_DB_USER MAGENTO_DB_NAME -e 'SELECT c.code,c.times_used,c.usage_limit,r.name FROM salesrule_coupon c JOIN salesrule r ON c.rule_id=r.rule_id WHERE c.code="COUPON_CODE";' 2>&1"

text

Generate coupons via REST (replace RULE_ID):
```bash
ssh -i MAGENTO_SSH_KEY -o StrictHostKeyChecking=yes MAGENTO_SSH_USER@MAGENTO_HOST "
TOKEN=\$(curl -s --cacert MAGENTO_CA_CERT -X POST MAGENTO_BASE_URL/rest/V1/integration/admin/token \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 618)May include surrounding context.

md
TOKEN=\$(curl -s --cacert MAGENTO_CA_CERT -X POST MAGENTO_BASE_URL/rest/V1/integration/admin/token \
  -H 'Content-Type: application/json' \
  -d '{\"username\":\"MAGENTO_ADMIN_USER\",\"password\":\"MAGENTO_ADMIN_PASS\"}' 2>/dev/null | tr -d '\"')
curl -s --cacert MAGENTO_CA_CERT -X POST MAGENTO_BASE_URL/rest/V1/salesRules/RULE_ID/coupons/generate \
  -H \"Authorization: Bearer \$TOKEN\" \
  -H 'Content-Type: application/json' \
  -d '{\"couponSpec\":{\"rule_id\":RULE_ID,\"qty\":5,\"length\":10,\"format\":\"alphanum\",\"prefix\":\"PROMO-\"}}' 2>/dev/null

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 711)May include surrounding context.

Product search (replace SEARCH_TERM):

bash
ssh -i MAGENTO_SSH_KEY -o StrictHostKeyChecking=yes MAGENTO_SSH_USER@MAGENTO_HOST \
  "curl -s --cacert MAGENTO_CA_CERT -X POST MAGENTO_BASE_URL/graphql -H 'Content-Type: application/json' \
   -d '{\"query\":\"{products(search:\\\"SEARCH_TERM\\\",pageSize:5){items{sku name price{regularPrice{amount{value currency}}}}}}\"}' 2>/dev/null | python3 -m json.tool"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 718)May include surrounding context.

Category list:

bash
ssh -i MAGENTO_SSH_KEY -o StrictHostKeyChecking=yes MAGENTO_SSH_USER@MAGENTO_HOST \
  "curl -s --cacert MAGENTO_CA_CERT -X POST MAGENTO_BASE_URL/graphql -H 'Content-Type: application/json' \
   -d '{\"query\":\"{categoryList{id name url_key level children{id name url_key}}}\"}' 2>/dev/null | python3 -m json.tool"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 884)May include surrounding context.

Search broken:

bash
ssh -i MAGENTO_SSH_KEY -o StrictHostKeyChecking=yes MAGENTO_SSH_USER@MAGENTO_HOST "
  curl -s -X PUT 'MAGENTO_OS_URL/*/_settings' -H 'Content-Type: application/json' -d '{\"index\":{\"number_of_replicas\":0}}' 2>/dev/null
  sudo -u MAGENTO_WEB_USER MAGENTO_PHP MAGENTO_WEB_ROOT/bin/magento indexer:reset catalogsearch_fulltext 2>&1
  sudo -u MAGENTO_WEB_USER MAGENTO_PHP MAGENTO_WEB_ROOT/bin/magento indexer:reindex catalogsearch_fulltext 2>&1
  sudo -u MAGENTO_WEB_USER MAGENTO_PHP MAGENTO_WEB_ROOT/bin/magento cache:flush 2>&1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
description: >
  Complete Magento 2 store administration via SSH key auth, REST API, GraphQL,
  and direct DB access. For server owners on their own infrastructure.
  SSH key auth and passwordless sudo required.
author: openclaw-community
license: MIT
tags: [magento, ecommerce, devops, store-admin, ssh, rest-api, graphql, composer]

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

md
description: >
  Complete Magento 2 store administration via SSH key auth, REST API, GraphQL,
  and direct DB access. For server owners on their own infrastructure.
  SSH key auth and passwordless sudo required.
author: openclaw-community
license: MIT
tags: [magento, ecommerce, devops, store-admin, ssh, rest-api, graphql, composer]

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 662)May include surrounding context.

md
description: >
  Complete Magento 2 store administration via SSH key auth, REST API, GraphQL,
  and direct DB access. For server owners on their own infrastructure.
  SSH key auth and passwordless sudo required.
author: openclaw-community
license: MIT
tags: [magento, ecommerce, devops, store-admin, ssh, rest-api, graphql, composer]

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 663)May include surrounding context.

md
description: >
  Complete Magento 2 store administration via SSH key auth, REST API, GraphQL,
  and direct DB access. For server owners on their own infrastructure.
  SSH key auth and passwordless sudo required.
author: openclaw-community
license: MIT
tags: [magento, ecommerce, devops, store-admin, ssh, rest-api, graphql, composer]

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 664)May include surrounding context.

md
description: >
  Complete Magento 2 store administration via SSH key auth, REST API, GraphQL,
  and direct DB access. For server owners on their own infrastructure.
  SSH key auth and passwordless sudo required.
author: openclaw-community
license: MIT
tags: [magento, ecommerce, devops, store-admin, ssh, rest-api, graphql, composer]

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 675)May include surrounding context.

md
description: >
  Complete Magento 2 store administration via SSH key auth, REST API, GraphQL,
  and direct DB access. For server owners on their own infrastructure.
  SSH key auth and passwordless sudo required.
author: openclaw-community
license: MIT
tags: [magento, ecommerce, devops, store-admin, ssh, rest-api, graphql, composer]

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 690)May include surrounding context.

md
description: >
  Complete Magento 2 store administration via SSH key auth, REST API, GraphQL,
  and direct DB access. For server owners on their own infrastructure.
  SSH key auth and passwordless sudo required.
author: openclaw-community
license: MIT
tags: [magento, ecommerce, devops, store-admin, ssh, rest-api, graphql, composer]

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 691)May include surrounding context.

md
description: >
  Complete Magento 2 store administration via SSH key auth, REST API, GraphQL,
  and direct DB access. For server owners on their own infrastructure.
  SSH key auth and passwordless sudo required.
author: openclaw-community
license: MIT
tags: [magento, ecommerce, devops, store-admin, ssh, rest-api, graphql, composer]

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 819)May include surrounding context.

md
description: >
  Complete Magento 2 store administration via SSH key auth, REST API, GraphQL,
  and direct DB access. For server owners on their own infrastructure.
  SSH key auth and passwordless sudo required.
author: openclaw-community
license: MIT
tags: [magento, ecommerce, devops, store-admin, ssh, rest-api, graphql, composer]

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 866)May include surrounding context.

md
description: >
  Complete Magento 2 store administration via SSH key auth, REST API, GraphQL,
  and direct DB access. For server owners on their own infrastructure.
  SSH key auth and passwordless sudo required.
author: openclaw-community
license: MIT
tags: [magento, ecommerce, devops, store-admin, ssh, rest-api, graphql, composer]

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
- name: MAGENTO_HOST
      description: Magento server IP or hostname
    - name: MAGENTO_SSH_USER
      description: SSH username (passwordless sudo required on server)
    - name: MAGENTO_SSH_KEY
      description: Path to SSH private key (e.g. ~/.ssh/magento_deploy)
    - name: MAGENTO_WEB_ROOT

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
- name: MAGENTO_HOST
      description: Magento server IP or hostname
    - name: MAGENTO_SSH_USER
      description: SSH username (passwordless sudo required on server)
    - name: MAGENTO_SSH_KEY
      description: Path to SSH private key (e.g. ~/.ssh/magento_deploy)
    - name: MAGENTO_WEB_ROOT

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

md
- name: MAGENTO_HOST
      description: Magento server IP or hostname
    - name: MAGENTO_SSH_USER
      description: SSH username (passwordless sudo required on server)
    - name: MAGENTO_SSH_KEY
      description: Path to SSH private key (e.g. ~/.ssh/magento_deploy)
    - name: MAGENTO_WEB_ROOT

Static analysis

No suspicious patterns detected.