T09 · Insecure Skill Coding Practices
- Location
skill.md:18- Finding
Unvalidated Shopify Store Domain Can Expose the Admin API Access Token
- Content
View full analysis
``` The access token is then available to the operator of the attacker-controlled server. ### Attack Path 1. An attacker influenc ...[truncated 1583 chars]- Remediation
View remediation
&2 exit 1 fi ``` 2. Reject values containing schemes, ports, paths, query strings, fragments, user-information components, whitespace, or control characters. Accept only a hostname, not an arbitrary URL. 3. Prefer a trusted wrapper script that performs validation centrally instead of asking users or agents to interpolate environment variables into raw `curl` commands repeatedly. 4. Restrict transport behavior explicitly: ```bash curl \ --proto '=https' \ --proto-redir '=https' \ --max-redirs 0 \ "https://${SHOPIFY_STORE_DOMAIN}/admin/api/2024-10/orders.json" \ -H "X-Shopify-Access-Token: ${SHOPIFY_ACCESS_TOKEN}" ``` 5. Apply least privilege to the Shopify custom application. Grant only the read or write scopes needed for the current workflow rather than all scopes listed by the skill. 6. Require explicit user confirmation before destructive or financially sensitive actions, including deletion, cancellation, inventory replacement, transaction capture, refunds, and webhook changes. 7. Store the access token in an approved secret manager, prevent it from appearing in logs or shell tracing, rotate it periodically, and revoke it immediately if disclosure is suspected. 8. Add an optional allowlist for the exact expected store hostname so that even another valid `myshopify.com` hostname is rejected in deployments bound to a single store. ]]>
