Back to skill

Security audit

Shopline Builder

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent SHOPLINE setup helper, but it asks for sensitive store authority and performs live store changes in ways that are broader and less clearly controlled than its disclosures say.

Review before installing. Do not paste Shopify secrets, API tokens, or payment keys into chat; enter credentials only in verified first-party or trusted app pages and revoke temporary keys after use. Require an isolated browser session, approve any product, price, image, payment, shipping, app install, or migration action before it is applied, and avoid letting the skill use your personal browser profile.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:876
Finding

Overprivileged Shopify Application Secret Is Collected Through Chat and Submitted to a Third-Party Migration Service

Content
View full analysis
Select scopes, select all read/write permissions under Admin API and Customer Account API. Shopify Payments permissions may be omitted. Fifth step: - Locate Client ID and Secret under Settings > Credentials. - Send the Client ID, Secret, and Shopify store handle to the AI so it can enter them into the migration tool. ``` ```javascript browser(action="act", request={"kind": "evaluate", "fn": """ (() => { const setter = Object.getOwnPropertyDescriptor( window.HTMLInputElement.prototype, 'value' ).set; const inputs = Array.from(document.querySelectorAll('input')) .filter(i => i.offsetParent !== null); setter.call(inputs[1], ''); inputs[1].dispatchEvent(new Event('input', {bubbles:true})); setter.call(inputs[2], ''); inputs[2].dispatchEvent(new Event('input', {bubbles:true})); setter.call(inputs[3], ''); inputs[3].dispatchEvent(new Event('input', {bubbles:true})); return inputs[1].value + ' | ' + inputs[2].value.slice(0,8) + '...'; })() """}) browser(action="screenshot") ``` ```text The migration plugin is hosted at admin.innovelabs.com and is cross-origin from the SHOPLINE administration interface. A signed URL is required to enter it. ``` ### Technical Analysis The Skill directs users to grant all read/write permissions under bot ...[truncated 2907 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:10
Finding

Authenticated Personal Browser Profile Use Contradicts the Declared Isolation Boundary

Content
View full analysis
This Skill uses the isolated openclaw browser to operate SHOPLINE administration pages. It does not use profile="user" or chrome-relay, connect to the user's personal browser, or access user cookies or other tabs. ``` ```text This Skill always uses the isolated openclaw browser. Do not use profile="user" or chrome-relay. A CDP connection can technically access every user tab and cookie and cannot be constrained at the Skill layer, so it does not comply with least privilege. ``` ```python browser( action="navigate", url="https://.myshopline.com/admin/products/add", profile="user" ) browser(action="snapshot", profile="user") browser( action="navigate", url="https://.myshopline.com/admin/settings/payments", profile="user" ) browser(action="snapshot", profile="user") browser( action="navigate", url="https://.myshopline.com/admin/settings/delivery", profile="user" ) browser(action="snapshot", profile="user") browser( action="navigate", url="https://.myshopline.com/admin/app-store", profile="user" ) browser(action="tabs", profile="user") ``` ### Technical Analysis The declared permission model states that the Skill uses only an isolated `openclaw` profile and explicitly does not connect to the user's personal browser. It further acknowledges that `profile="user"` can technically expose all browser tabs and cookies and cannot be adequately constrained at the Skill layer. The operational instructions contradict that declaration by repeatedly invoking `profile="user"` for authenticated product publication, pay ...[truncated 1856 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
references/flow-newbie.md:7
Finding

Mandatory Response Templates Inject Attribution-Tracked Promotional Links

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly assures users it always uses an isolated openclaw browser and never connects to the user's personal browser, but later operational steps switch to profile="user" for authenticated admin actions. That contradiction is dangerous because it defeats the stated isolation guarantees and could expose the user's real browser session, cookies, tabs, or broader browsing context to automation beyond what the manifest discloses.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to generate, upload, and publish a product automatically without separately warning the user that live storefront content will be created and made visible. This is dangerous because it can alter the merchant's catalog, pricing, descriptions, and public-facing store state without informed approval, causing reputational, operational, or legal harm.

Content

No source excerpt is available for this finding.

Scope Creep

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill uses profile="user" for browser actions even though the manifest only declares sandboxed browser use via openclaw. This is a true permission/scope violation because the executable instructions request broader browser access than the user was told to expect, enabling actions in a real logged-in session with elevated exposure to account state and potentially unrelated browser data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill automatically changes shipping zones and rates using hard-coded defaults without warning the user that fulfillment settings for a live store will be modified. This is risky because incorrect shipping rules can directly affect customer charges, order acceptance, fulfillment obligations, and merchant liability.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill asks the user to provide Shopify Client ID and Secret through the agent workflow so the agent can enter them into a migration tool. Requesting high-value credentials/secrets through the conversational channel materially increases the risk of credential exposure, reuse, and unauthorized access to the user's Shopify resources.

Content

Scanner excerpt · SKILL.md (reported line 876)May include surrounding context.

md
🎉 搬迁插件已安装!接下来需要你在 Shopify 这边做一个简单的授权配置,我来一步步告诉你怎么做。

**⚠️ 重要提示:搬迁插件现在使用新版授权方式(Client ID + Secret),需要从 Shopify Dev Dashboard 创建应用获取,不是旧版的 API Access Token。**

请按以下步骤操作(约5分钟):

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The fallback instructions tell users to generate and use a Shopify API Access Token if the plugin shows an older interface. That expands the skill into soliciting even more sensitive long-lived credentials, which could grant broad API access if exposed or mishandled.

Content

Scanner excerpt · SKILL.md (reported line 904)May include surrounding context.

md
>
> ⚠️ **注意事项:**
> - 如果点 Install app 报错「此应用无法安装」:进入 Settings → Distribution → 选「自定义分发」→ 填入店铺域名 → 点 Generate Link → 在新标签页打开链接安装
> - 如果搬迁插件界面仍然是要求输入 API Access Token 的旧版界面,则用旧版流程(在 Shopify 后台 Settings → Apps → Develop apps 里生成 Access Token)

---

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The technical notes explicitly direct the agent to handle a Shopify Secret and distinguish it from an older Access Token format, confirming that the workflow is designed around agent-mediated entry of sensitive credentials. In context, this is dangerous because the skill combines credential solicitation with automated cross-system actions, raising the blast radius if the secret is leaked or abused.

Content

Scanner excerpt · SKILL.md (reported line 1026)May include surrounding context.

md
> - 搬迁插件托管在 `admin.innovelabs.com`,与 SHOPLINE 后台跨域,需用签名 URL 方式进入
> - 签名 URL 有效期约 30 分钟,过期需重新调 `/admin/appstore/get-install-url` 获取
> - 三个 input 中 index 0 为隐藏字段,从 index 1 开始是可见字段
> - Secret 字段填的是 Shopify Dev Dashboard → Settings → Credentials 里的 **Secret**(格式 `shpss_...`,不是旧版 Access Token `shpat_...`)
> - 模块选择 checkbox 为 Vue 组件,必须用 `elementFromPoint` + 完整鼠标事件序列点击,JS click/dispatchEvent 无效
> - 订单必须在商品+客户+折扣码全部勾选后再勾,否则弹依赖提示

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The changelog explicitly documents handling of sensitive material such as Client ID, Secret values in shpss_... format, and signed authorization URLs with a 30-minute validity window, but provides no warning or handling guidance. In the context of an automation skill for store administration and migration, this normalizes exposure of credentials and transient auth artifacts that could be logged, copied into prompts, screenshots, or shared inappropriately, increasing the risk of account or app compromise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger list includes broad phrases such as “我想开一个独立站”, “独立站建站教程”, “start selling on SHOPLINE”, and “migrate to SHOPLINE”, which can match ordinary informational questions rather than clear requests for this automation skill. The file does not provide exclusion conditions or negative examples to distinguish casual advice-seeking from consent to full browser-driven account setup and configuration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instructions mandate a fixed Chinese information-collection script immediately after triggering, despite the trigger list including English phrases and the file containing English resources. This creates a language/locale policy issue because the skill does not offer the user a language choice or require opt-in before forcing Chinese responses.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill fetches third-party images via shell commands and uploads them as store products automatically, without asking the user to review or approve the content. This is risky because it introduces unvetted external assets into a user's storefront, can create copyright/compliance issues, and exceeds the minimally necessary behavior for account setup by publishing business content on the user's behalf.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The package description is written entirely in Chinese and presents the skill as a general SHOPLINE site-building assistant, but it does not indicate that Chinese is optional, user-selectable, or required for a region-specific use case. This creates a natural-language locale policy concern because the skill appears to assume a fixed language without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains user-facing FAQ content only in Chinese, including the title and all answers, but it does not indicate that users may choose another language or that the skill is intentionally limited to Chinese-language operation. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file instructs partners to fill in prospective customers' contact and company information for lead submission, which affects third-party personal data handling. The surrounding text does not include any warning to ensure consent, lawful basis, or privacy disclosure before sharing that data with SHOPLINE.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file instructs users to migrate customer, order, and product data from other channels into a development store, which can involve sensitive commercial and personal information. Although there is a backup note for ad data elsewhere, there is no clear warning here about protecting personal data, validating permissions, or confirming backups before migration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The WooCommerce section instructs users to generate an API Key and API Secret and paste them into the migration tool, but it does not warn that these are sensitive credentials that must be handled like passwords. In an AI-guided workflow, omission of secrecy guidance increases the chance users will expose keys in chat transcripts, screenshots, shared notes, or to an untrusted tool instance, enabling unauthorized API access to store data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Shoplazza flow tells users to generate and provide an API Token without clearly labeling it as sensitive credential material. Because this document is meant for AI-driven guidance, users may incorrectly disclose the token back to the assistant or other channels, which could permit unauthorized access to the connected store or private application scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The payment setup guidance asks for a Stripe API Key but does not warn that it is highly sensitive payment credential material. Exposure of a Stripe secret key can allow unauthorized payment configuration changes, access to financial data, or abuse of the merchant account depending on the key type and scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document is entirely written as a fixed Chinese guidance script, starting with a Chinese-only title and continuing throughout without indicating that other languages are available. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file presents all operational content in Chinese, including headings, notes, and maintenance instructions, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy rules, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The heading labels the file as an English FAQ, but the surrounding metadata and much of the structural text use Chinese. This creates a natural-language locale mismatch and may implicitly force or misrepresent language expectations without offering the user a choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · references/faq-en.md (reported line 118)May include surrounding context.

md
Extending Functionality: Apps and Developer Tools

Beyond design, SHOPLINE allows you to integrate apps with your chosen theme to expand functionality. You can add features like secure payment gateways, social media feeds, and live chat support, making your services more comprehensive.

For those with technical knowledge, SHOPLINE even offers the freedom to customize themes using HTML, CSS, JavaScript, and JSON. Craft unique design elements, custom features, and user experiences that align with your brand. You can opt for the SHOPLINE CLI and API for in-depth development, or the Code Editor for quick modifications. For more details, please visit our Development Center.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is in Chinese but explicitly states that the SHOPLINE Academy course is currently only available in English. Under the stated policy, forcing a specific language without offering a language choice or opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This file presents the entire migration flow in Chinese and phrases it as the guidance the AI should use, but it does not offer the user a language option or state that the skill is intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.