Back to skill

Security audit

Shopify助手-免费版

Security checks across malware telemetry and agentic risk

Overview

This Shopify helper is not deceptive, but it needs review because it can run commands and publish theme changes without clear safeguards.

Install only if you intend to use it for Shopify projects. Before allowing command execution or file writes, confirm the target store and theme, use a draft or unpublished theme where possible, keep a backup, and require explicit approval before `shopify auth login`, `theme pull`, or `theme push`.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger condition '需要代码生成、编程辅助、调试测试、开发部署时使用' is broad enough to activate this skill for many generic software tasks beyond Shopify-specific work. Because the skill has exec and write capabilities, an overly permissive trigger increases the chance that an agent invokes it in inappropriate contexts and performs file changes or shell actions the user did not intend.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The statement that users can trigger the scenario through natural-language instructions without specific constraints is ambiguous and creates unsafe invocation boundaries. In an agent environment, vague NL activation can cause the skill to interpret unrelated prompts as authorization to execute commands or modify theme files.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly declares read, exec, and write tools, but the description does not clearly warn that it may run shell commands or modify local files. This is dangerous because users may treat it as advisory documentation while the agent interprets it as permission to execute commands and change project assets.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The guidance includes 'shopify theme push' without an explicit warning that it can deploy changes to a live Shopify store. In context, this is especially risky because the skill is aimed at personal sellers and small merchants, who may unintentionally publish broken themes, overwrite production work, or expose storefront issues to customers.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.