Back to skill

Security audit

Shop

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Shop shopping skill, but it needs Review because it asks for a mutable global CLI install and includes unnecessary local identity and third-party IP handling in checkout/auth flows.

Review this before installing if you are comfortable with a globally installed Shopify CLI, Shop sign-in, order-history access, checkout/payment flows, and sending product-search images or checkout network metadata to external services. Use a pinned or isolated CLI install where possible, avoid delegated spending unless you understand the budget controls, and revoke Shop connections if you no longer want the agent to access your account.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/direct-api.md:21
Finding

Unnecessary Access to Agent Identity Files During OAuth Device Registration

Content
View full analysis
- # e.g. Max - Mac Mini; name from IDENTITY.md (OpenClaw) / ~/.hermes/SOUL.md (Hermes) ``` ### Technical Analysis The instructions direct the Agent to read a name from `IDENTITY.md` or `~/.hermes/SOUL.md` and include it in an outbound OAuth device-authorization request. These files may contain Agent identity, profile, behavioral, or other persistent configuration information. OAuth device registration only requires a descriptive device label. Reading persistent Agent identity files is therefore not necessary for the Skill’s shopping functionality and violates least-privilege principles. It also creates an avoidable path through which information derived from local Agent state is transmitted to an external service. The instructions specify use of the name rather than the entire file, which limits the likely disclosure. There is no evidence that arbitrary file contents or credentials are intentionally exfiltrated. ### Attack Path 1. The Skill is invoked while the Shop CLI is unavailable. 2. The Agent follows the manual device-authorization instructions. 3. The Agent opens `IDENTITY.md` or `~/.hermes/SOUL.md`. 4. It extracts identity information from that persistent file. 5. The extracted value is placed in the `device_name` parameter. 6. The value is transmitted to `https://accounts.shop.app/oauth/device`. ### Impact Assessment The behavior grants the Skill unnecessary read access to persistent Agent identity or profile state. Information derived from that state can be disclosed to Shopify’s account service. The confirm ...[truncated 251 chars]
Remediation
View remediation

other

Warning
Location
references/direct-api.md:77
Finding

Buyer Public IP Is Collected Through a Third Party and Forwarded to Merchant Domains

Content
View full analysis
Content-Type: application/json Shopify-Buyer-Ip: Fetch the buyer's public IP immediately before checkout calls and keep it in memory only. Shopify forwards it as `Shopify-Buyer-Ip` to run checkout fraud/risk checks, the same as any web checkout: GET https://api.ipify.org?format=json ``` ### Technical Analysis The checkout workflow explicitly contacts `api.ipify.org`, an external third-party service, to determine the buyer’s public IP address. It then forwards that address through the `Shopify-Buyer-Ip` header to a merchant-specific checkout endpoint. A public IP address is privacy-relevant network metadata that can reveal an approximate location and correlate activity across services. This design exposes the buyer’s connection metadata to both ipify and each participating merchant, expanding the checkout trust boundary beyond Shopify and the selected merchant. The documented purpose is merchant fraud and risk analysis, so forwarding an IP address may be functionally related to checkout. However, using an unrelated third-party IP-discovery service and requiring this collection without an explicit necessity check or user disclosure exceeds the minimum network access needed for catalog search and may exceed what is required for checkout if the header is optional. The instructions correctly require the IP and checkout JWT to remain in memory. This reduces persistence risk but does not prevent disclosure during transmission. ### Attack Path 1. A signed-in buyer initiates a checkout. 2. The Agent sends a request to `https://api.ipify.org?format=json`. 3. ipify observes the request and returns the buyer’s public IP. 4. T ...[truncated 1118 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Globally Installed CLI Uses an Unpinned Mutable Package Version

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

shop --help

text

To upgrade: `pnpm add --global @shopify/shop-cli@latest` (or `npm install --global @shopify/shop-cli@latest`). Uninstall: `pnpm rm -g @shopify/shop-cli` (or `npm rm -g @shopify/shop-cli`).

**Reference files:**
- [catalog-mcp.md](references/catalog-mcp.md) — direct catalog MCP calls + manual token exchange

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

shop --help

text

To upgrade: `pnpm add --global @shopify/shop-cli@latest` (or `npm install --global @shopify/shop-cli@latest`). Uninstall: `pnpm rm -g @shopify/shop-cli` (or `npm rm -g @shopify/shop-cli`).

**Reference files:**
- [catalog-mcp.md](references/catalog-mcp.md) — direct catalog MCP calls + manual token exchange

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill explicitly encourages configuring a delegated spending budget so the agent can complete future purchases without per-purchase approval. In a shopping/payment context, reducing transaction-specific confirmation materially increases the risk of unauthorized or unintended purchases if the agent is manipulated, confused, or acts on ambiguous user input.

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

md
Rules: send it as its own distinct message (never combined with other text), at most once per session unless the user asks again, and never pressure — it's a convenience.

> Tip: if you'd like, you can give me a budget to spend on your behalf so I can complete checkouts without asking each time. Set a spending limit here: https://shop.app/account/settings/connections. Or, tell me *not interested*, and I'll remember not to offer it again.

## Orders
Queries return 1 result except for recent - use date filters or new queries if you can't find what you want first time. Requires sign-in. Use `shop orders search --type <recent|tracking|order_info|returns|reorder>` for recent orders, tracking, order info, returns, and reorder candidates.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly instructs sending user-provided images and location/context signals to an external catalog service, and even notes that images may contain personal data. In a shopping assistant context, those fields can reveal sensitive personal or household information, and the file does not pair that guidance with a clear requirement for informed user consent, minimization, or redaction before transmission.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/direct-api.md (reported line 233)May include surrounding context.

Payment Budget (Delegated Spending)

When the buyer enables purchasing without approval in Shop → Settings → Connections, Shop issues a budgeted wallet payment token. Read the remaining budget:

text
GET https://shop.app/pay/agents/payment_tokens

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/safety.md (reported line 24)May include surrounding context.

md
- Store only `access_token`, `refresh_token`, `device_id`, and `country` in the OS secret store.
- Keep token-exchange JWTs and UCP payment tokens memory-only.
- Never expose tokens, Authorization headers, card data, session IDs, full addresses, phone numbers, or payment credentials in user-visible output.
- Do not ask the user to paste tokens into chat.

## Prompt Injection

Static analysis

No suspicious patterns detected.