Back to skill

Security audit

Shopify Admin API

Security checks for vulnerabilities and agentic risk

Overview

This Shopify API skill is not deceptive, but it gives agents broad store-changing and money-moving examples without enough user-confirmation or safety scoping.

Install only if you are comfortable giving the agent Shopify Admin API authority. Use the narrowest Shopify scopes possible, validate the store domain before any token-bearing request, keep the access token in a secrets manager, and require explicit human approval before deletes, cancellations, inventory replacement, refunds, transaction captures, webhook changes, or customer notifications.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
skill.md:18
Finding

Unvalidated Shopify Store Domain Can Expose the Admin API Access Token

Content
View full analysis
``` The access token is then available to the operator of the attacker-controlled server. ### Attack Path 1. An attacker influenc ...[truncated 1583 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. Reject values containing schemes, ports, paths, query strings, fragments, user-information components, whitespace, or control characters. Accept only a hostname, not an arbitrary URL. 3. Prefer a trusted wrapper script that performs validation centrally instead of asking users or agents to interpolate environment variables into raw `curl` commands repeatedly. 4. Restrict transport behavior explicitly: ```bash curl \ --proto '=https' \ --proto-redir '=https' \ --max-redirs 0 \ "https://${SHOPIFY_STORE_DOMAIN}/admin/api/2024-10/orders.json" \ -H "X-Shopify-Access-Token: ${SHOPIFY_ACCESS_TOKEN}" ``` 5. Apply least privilege to the Shopify custom application. Grant only the read or write scopes needed for the current workflow rather than all scopes listed by the skill. 6. Require explicit user confirmation before destructive or financially sensitive actions, including deletion, cancellation, inventory replacement, transaction capture, refunds, and webhook changes. 7. Store the access token in an approved secret manager, prevent it from appearing in logs or shell tracing, rotate it periodically, and revoke it immediately if disclosure is suspected. 8. Add an optional allowlist for the exact expected store hostname so that even another valid `myshopify.com` hostname is rejected in deployments bound to a single store. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly advertises full read/write Shopify Admin API access over highly sensitive store resources, including orders, customers, inventory, refunds, returns, transactions, and webhooks, but does not provide safety guardrails, approval requirements, or impact warnings. In an agent context, this materially increases the risk of destructive, privacy-impacting, or financial actions being taken without informed user consent.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 19)May include surrounding context.

md
### Environment Variables

- `SHOPIFY_STORE_DOMAIN` - Your store's myshopify.com domain (e.g., `my-store.myshopify.com`)
- `SHOPIFY_ACCESS_TOKEN` - Admin API access token from custom app

### Required API Scopes

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 46)May include surrounding context.

md
### Environment Variables

- `SHOPIFY_STORE_DOMAIN` - Your store's myshopify.com domain (e.g., `my-store.myshopify.com`)
- `SHOPIFY_ACCESS_TOKEN` - Admin API access token from custom app

### Required API Scopes

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 40)May include surrounding context.

X-Shopify-Access-Token: $SHOPIFY_ACCESS_TOKEN

text

### Getting an Access Token

1. Go to your Shopify Admin > Settings > Apps and sales channels
2. Click "Develop apps" > "Create an app"

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation provides direct delete examples for products and, elsewhere in the skill, similarly destructive operations for customers, collections, collects, and webhooks without any caution that these actions may be irreversible or operationally disruptive. In an automation setting, such examples normalize unsafe behavior and can lead an agent or user to execute destructive actions unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The refund and transaction sections include operations that can issue refunds, capture funds, and notify customers, yet there is no warning that these actions can have real financial consequences and customer-facing effects. In a live commerce environment, misuse can cause monetary loss, accounting discrepancies, and reputational damage.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 57)May include surrounding context.

List Orders

bash
curl "https://$SHOPIFY_STORE_DOMAIN/admin/api/2024-10/orders.json" \
  -H "X-Shopify-Access-Token: $SHOPIFY_ACCESS_TOKEN"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 702)May include surrounding context.

bash
# First request
curl "https://$SHOPIFY_STORE_DOMAIN/admin/api/2024-10/products.json?limit=50" \
  -H "X-Shopify-Access-Token: $SHOPIFY_ACCESS_TOKEN" \
  -i

Static analysis

No suspicious patterns detected.