Back to skill

Security audit

Shopify Category Collector

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Shopify category scraper, but it has broad browser/network reach and local screenshot output that are not tightly scoped.

Review before installing. Use this only for public storefront pages you intentionally choose, preferably in an isolated environment. Do not run it against authenticated dashboards, internal URLs, localhost services, cloud metadata addresses, or sites supplied by an untrusted party. Check the output directory because it saves screenshots as well as CSV files, and consider pinning dependencies and using an approved npm registry before installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
collect.js:30
Finding

Unrestricted Browser Navigation Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation
{ const requestUrl = new URL(route.request().url()); if (!(await isAllowedNetworkDestination(requestUrl))) { return route.abort(); } return route.continue(); }); ``` 5. Validate every redirect destination. Browser-level request interception should remain active for the entire context so that redirects and subresources receive the same checks. 6. If the intended use is limited to approved storefronts, enforce an explicit hostname allowlist. 7. Apply the same centralized URL validation helper to every collector variant rather than maintaining separate implementations. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
collect-improved.js:57
Finding

Missing Same-Origin Enforcement Allows Attacker-Controlled Cross-Origin Navigation

Content
View full analysis
{ const links = Array.from(document.querySelectorAll('a[href]')); const result = []; links.forEach(link => { const href = link.getAttribute('href'); const text = link.textContent.trim(); // 只收集站内链接 if (href && !href.includes('#') && !href.includes('javascript:')) { result.push({ href: href, text: text }); } }); return result; }); ``` ```js const collectionLinks = allLinks.filter(link => { return link.href.includes('/collections/') || link.href.includes('/categories/'); }); ``` ```js for (let i = 0; i < collectionLinks.length; i++) { const link = collectionLinks[i]; // 转换为完整 URL let fullUrl = link.href; if (link.href.startsWith('/')) { fullUrl = new URL(link.href, startUrl).href; } // 去重 if (seen.has(fullUrl)) { continue; } seen.add(fullUrl); // 过滤掉非分类链接 if (fullUrl.includes('/page/') || fullUrl.includes('/cart') || fullUrl.includes('/checkout') || fullUrl.includes('/account') || fullUrl.includes('/search')) { continue; } console.log(`[${i+1}/${collectionLinks.length}] 处理: ${link.text} -> ${fullUrl}`); try { await page.goto(fullUrl, { waitUntil: 'domcontentloaded', timeout: 30000 }); ``` ### Technical Analysis The comment states that only internal links are collected, but the implementation never compares the candidate link's origin with the origin of `startUrl`. The code only checks whether a raw `href`: - Is present. - Does not contain `#`. - Does not contain the literal string `javascript:`. - Contains `/collections/` or `/categories/`. An absolute cross-origin URL therefore passes the filter. For example, a malicious storefront could include a link ...[truncated 1955 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
package-lock.json:20
Finding

Dependency Lockfile Retrieves Packages from a Third-Party Registry Mirror

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A skill that advertises structured category extraction and CSV export but actually performs console debugging and limited inspection creates an integrity and trust problem. In security-sensitive agent ecosystems, hidden or undeclared behavior can mask broader collection activity and make review, sandboxing, and least-privilege decisions inaccurate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill that advertises structured category extraction and CSV export but actually performs console debugging and limited inspection creates an integrity and trust problem. In security-sensitive agent ecosystems, hidden or undeclared behavior can mask broader collection activity and make review, sandboxing, and least-privilege decisions inaccurate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A skill that advertises structured category extraction and CSV export but actually performs console debugging and limited inspection creates an integrity and trust problem. In security-sensitive agent ecosystems, hidden or undeclared behavior can mask broader collection activity and make review, sandboxing, and least-privilege decisions inaccurate.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a Shopify category link collector focused on extracting real category hierarchy from Shopify navigation, including Ajax lazy-loaded dropdown menus. In contrast, the README explicitly states support for /product-category/... WooCommerce URLs and emphasizes parsing hierarchy from URL slugs, which broadens behavior beyond Shopify navigation extraction.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the full README content require Chinese comprehension, which effectively forces a specific language for users. The policy allows fixed language only when there is user opt-in or a clearly justified region-specific constraint, neither of which is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains natural-language documentation, CLI help text, and runtime messages exclusively in Chinese. Because the skill does not offer user opt-in for language selection or explain that it is intentionally limited to Chinese-speaking users, it creates a language/locale policy concern under the natural-language policy rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file presents its description, usage guidance, and runtime messages exclusively in Chinese, with no option to choose another language. This creates a language policy concern because the skill imposes a locale on all users rather than offering a choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script automatically captures a full-page screenshot of whatever target site the operator provides and writes it to disk without any prompt, opt-in, or minimization controls. Screenshots can unintentionally collect sensitive page content such as account details, internal dashboards, or personal data if the tool is used against authenticated or non-public pages, so the privacy risk is real even though the feature appears intended for debugging.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language instructions, comments, and runtime messages entirely in Chinese, including the usage/help text shown to users. Under the policy, forcing a specific language without user opt-in is a locale-policy violation unless the constraint is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code opens a user-supplied website, captures page content, saves a full-page screenshot, and later writes collected data to disk. Although there are progress logs, there is no explicit warning in comments, usage text, or user-facing output that the script will persist potentially sensitive page contents locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains natural-language documentation and output labels entirely in Chinese, including the tool description, usage notes, and CSV headers. Because the skill does not offer an opt-in language choice or explain that it is intentionally limited to a Chinese-speaking context, it violates the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The main command-line help text and status logs are presented only in Chinese, which forces a specific language experience on all users. This is a natural-language policy issue because the file does not provide any mechanism to choose language or justify the locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs a file write by saving a full-page screenshot to a local path, which may capture page contents and persist them on disk. While the code logs after saving, there is no prior warning, confirmation, or explanatory comment/disclosure that this data will be written locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script prints user-facing status messages in Chinese at multiple points, such as the homepage, navigation structure, and menu statistics logs. Because the file provides no opt-in, fallback, or justification for a Chinese-only interface, it creates a natural-language locale policy concern under the requirement to avoid forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The setup instructions invoke 'npx playwright' without pinning an explicit version, which can fetch and execute whatever version is current at runtime. That creates a supply-chain risk: a malicious or compromised upstream release, or an unexpected breaking update, could execute arbitrary code during setup or install.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

SQP-3 applies to all file types and covers natural-language policy issues such as forcing a specific language without opt-in. The document presents all instructions and descriptions in Chinese only, with no alternative language option or note that the locale restriction is intentional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that the skill automatically exports CSV files and saves page screenshots, but it does not clearly warn users that it writes to disk and captures visual page content. In a web-automation context, screenshots can unintentionally collect sensitive information from storefronts, admin sessions, or authenticated pages, and silent file output reduces informed consent and auditability.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest focuses on collecting category links, handling Ajax-loaded menus, separating category levels into CSV cells, and outputting CSV. Automatic screenshot saving is an additional behavior not justified by that description and suggests extra data collection/output beyond the declared purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file's comments, console messages, and CLI help are written exclusively in Chinese, with no option to select another language. Per the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language description is entirely in Chinese and presents the skill as Chinese-localized without mentioning any language choice or optional locale support. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation when no justification or choice is documented.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
87% confidence
Finding

Using a caret version range for a dependency allows newer compatible releases to be installed automatically, which can introduce unreviewed code changes or supply-chain risk over time. In a scraping tool that depends on a large browser automation library, this slightly increases exposure if an upstream release is compromised or contains a breaking security issue.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"category-collector": "./collect.js"
  },
  "dependencies": {
    "playwright": "^1.40.0"
  },
  "keywords": [
    "scraper",

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
collect-improved.js:234

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
debug-liverpool.js:78