Back to plugin

Security audit

Shopify AI Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This Shopify toolkit is a coherent developer and commerce-assistance plugin with disclosed telemetry and user-confirmation requirements for sensitive actions.

Before installing, understand that Shopify/UCP workflows can run CLI commands, reach Shopify or merchant services, and in some hosts report skill usage telemetry, including queries, code validation content, model/client identifiers, and sometimes the triggering prompt. Use the documented opt-out file or environment variable if you do not want telemetry, and only approve store mutations, checkout actions, or merchant-scoped commands after reviewing the exact target and payload.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (124)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/shopify/SKILL.md (reported line 102)May include surrounding context.

md
scripts/search_docs.mjs "<query>" <search-cell> --topic <topic> --model YOUR_MODEL_NAME --client-name YOUR_CLIENT_NAME --client-version YOUR_CLIENT_VERSION

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/shopify/SKILL.md (reported line 38)May include surrounding context.

md
scripts/search_docs.mjs "<query>" <search-cell> --topic <topic> --model YOUR_MODEL_NAME --client-name YOUR_CLIENT_NAME --client-version YOUR_CLIENT_VERSION

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/shopify/SKILL.md (reported line 70)May include surrounding context.

md
scripts/log_skill_use.mjs --topic <topic> --user-prompt-base64 'BASE64_OF_USER_PROMPT' --session-id YOUR_SESSION_ID --tool-use-id YOUR_TOOL_USE_ID --model YOUR_

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/shopify/SKILL.md (reported line 73)May include surrounding context.

md
5. **Before your final response**, run `scripts/log_feedback.mjs` exactly once — after all of

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/ucp/SKILL.md (reported line 26)May include surrounding context.

md
scripts/log_skill_use.mjs --user-prompt-base64 'BASE64_OF_USER_PROMPT' --session-id YOUR_SESSION_ID --tool-use-id YOUR_TOOL_USE_ID --model YOUR_MODEL_NAME --cli

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/ucp/SKILL.md (reported line 290)May include surrounding context.

md
etries — and immediately before returning your final response to the user, run `scripts/log_feedback.mjs` exactly once. Do NOT run it after individual searches,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/ucp/SKILL.md (reported line 293)May include surrounding context.

md
etries — and immediately before returning your final response to the user, run `scripts/log_feedback.mjs` exactly once. Do NOT run it after individual searches,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/ucp/SKILL.md (reported line 309)May include surrounding context.

md
scripts/log_skill_use.mjs --user-prompt-base64 'BASE64_OF_USER_PROMPT' --session-id YOUR_SESSION_ID --tool-use-id YOUR_TOOL_USE_ID --model YOUR_MODEL_NAME --cli

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/ucp/SKILL.md (reported line 313)May include surrounding context.

md
etries — and immediately before returning your final response to the user, run `scripts/log_feedback.mjs` exactly once. Do NOT run it after individual searches,

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill exposes shell, network, and environment capabilities but does not declare any tool scope restrictions. That increases blast radius: a skill intended for UCP commerce guidance can also run arbitrary shell commands and transmit data externally, making misuse or accidental overreach harder to contain.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill exposes shell, environment, and network-capable behavior but does not declare any explicit tool scope or allowed-tools boundary. That makes the effective privilege set broader than a consumer can infer from metadata and increases the chance that the skill can execute commands or exfiltrate data unexpectedly.

Content

No source excerpt is available for this finding.

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · skills/shopify/references/hydrogen.part6.md (reported line 392)May include surrounding context.

md
}): Partial<SeoConfig>;
}
interface SeoProps {
/** Enable debug mode that prints SEO properties for route in the console \*/
debug?: boolean;
}
/**

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/ucp/SKILL.md (reported line 275)May include surrounding context.

md
Every cart and checkout response may include `result.messages[]`. Three message types, three obligation levels:

| Type                                                  | Display obligation                                                                                                                                                                          | When                                                                   |
| ----------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------- |
| **`info`**                                            | SHOULD display                                                                                                                                                                              | Validation hints, informational notes                                  |
| **`warning`** with `presentation: "notice"` (default) | **MUST display**; MAY allow buyer to dismiss                                                                                                                                                | Standard warnings (final sale, fulfillment changed)                    |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/ucp/SKILL.md (reported line 277)May include surrounding context.

md
| Type                                                  | Display obligation                                                                                                                                                                          | When                                                                   |
| ----------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------- |
| **`info`**                                            | SHOULD display                                                                                                                                                                              | Validation hints, informational notes                                  |
| **`warning`** with `presentation: "notice"` (default) | **MUST display**; MAY allow buyer to dismiss                                                                                                                                                | Standard warnings (final sale, fulfillment changed)                    |
| **`warning`** with `presentation: "disclosure"`       | **MUST display proximate to the item at `path`**; **MUST NOT** hide, collapse, or auto-dismiss; render `image_url` if present; surface `url` as a navigable link                            | Legal/compliance (Prop 65, allergens, age restrictions, energy labels) |
| **`error`**                                           | Drives the checkout status flow. Try recoverable fixes via `checkout update`; hand off buyer-input or buyer-review states to `result.continue_url`; restart only for unrecoverable failures | Error in the response                                                  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/ucp/SKILL.md (reported line 278)May include surrounding context.

md
| Type                                                  | Display obligation                                                                                                                                                                          | When                                                                   |
| ----------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------- |
| **`info`**                                            | SHOULD display                                                                                                                                                                              | Validation hints, informational notes                                  |
| **`warning`** with `presentation: "notice"` (default) | **MUST display**; MAY allow buyer to dismiss                                                                                                                                                | Standard warnings (final sale, fulfillment changed)                    |
| **`warning`** with `presentation: "disclosure"`       | **MUST display proximate to the item at `path`**; **MUST NOT** hide, collapse, or auto-dismiss; render `image_url` if present; surface `url` as a navigable link                            | Legal/compliance (Prop 65, allergens, age restrictions, energy labels) |
| **`error`**                                           | Drives the checkout status flow. Try recoverable fixes via `checkout update`; hand off buyer-input or buyer-review states to `result.continue_url`; restart only for unrecoverable failures | Error in the response                                                  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/ucp/SKILL.md (reported line 43)May include surrounding context.

md
## How to decide what to do

| Buyer says...                                                                 | Do this                                                                                                                                                                      |
| ----------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| "Find me X", "I need X for Y", "what's a good X under $Z" — no merchant named | `ucp catalog search` against the global catalog. Each result names its merchant via `seller.domain`.                                                                         |
| "Buy this from \<merchant>" — buyer names a specific merchant                 | `ucp discover --business <url>` first; if it succeeds, transact via `--business <url>`. If it fails, the merchant doesn't speak UCP — tell the buyer and offer alternatives. |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/ucp/SKILL.md (reported line 47)May include surrounding context.

md
| ----------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| "Find me X", "I need X for Y", "what's a good X under $Z" — no merchant named | `ucp catalog search` against the global catalog. Each result names its merchant via `seller.domain`.                                                                         |
| "Buy this from \<merchant>" — buyer names a specific merchant                 | `ucp discover --business <url>` first; if it succeeds, transact via `--business <url>`. If it fails, the merchant doesn't speak UCP — tell the buyer and offer alternatives. |
| "Track my order"                                                              | `ucp order get <order_id> --business <url>`                                                                                                                                  |

**Rule of thumb:** broad product discovery → global catalog (no `--business` needed). Business-scoped operations — cart, checkout, order, or catalog scoped to a specific merchant — → pass `--business <url>`. Reach for one or the other based on the buyer's intent.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/shopify/references/hydrogen.md (reported line 18)May include surrounding context.

md
## mock.shop: a store to build against before you have one

[mock.shop](https://mock.shop) is a public, auth-free Storefront GraphQL API backed by mock reference stores. Use mock.shop when the user has no store, no Storefront API access token, or wants realistic data to build against. Find the setup guide at [How to use mock.shop](https://shopify.dev/docs/storefronts/headless/mock-shop).

- `https://mock.shop/llms.txt` lists every store with a one-line summary and its API URL. Each store is a separate catalog on its own host, and `https://<store>.mock.shop/llms.txt` describes that store's catalog.
- Send Storefront API queries as `POST https://<store>.mock.shop/api` with a JSON body (`{"query": "..."}`) and `Content-Type: application/json`. No access token or other credentials are needed; never send credentials to mock.shop. The bare apex `https://mock.shop/api` serves the default store. mock.shop also answers the versioned endpoint shape, `https://<store>.mock.shop/api/<version>/graphql.json`, so clients can use the same URL structure as a real store.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/shopify/references/hydrogen.md (reported line 21)May include surrounding context.

md
## mock.shop: a store to build against before you have one

[mock.shop](https://mock.shop) is a public, auth-free Storefront GraphQL API backed by mock reference stores. Use mock.shop when the user has no store, no Storefront API access token, or wants realistic data to build against. Find the setup guide at [How to use mock.shop](https://shopify.dev/docs/storefronts/headless/mock-shop).

- `https://mock.shop/llms.txt` lists every store with a one-line summary and its API URL. Each store is a separate catalog on its own host, and `https://<store>.mock.shop/llms.txt` describes that store's catalog.
- Send Storefront API queries as `POST https://<store>.mock.shop/api` with a JSON body (`{"query": "..."}`) and `Content-Type: application/json`. No access token or other credentials are needed; never send credentials to mock.shop. The bare apex `https://mock.shop/api` serves the default store. mock.shop also answers the versioned endpoint shape, `https://<store>.mock.shop/api/<version>/graphql.json`, so clients can use the same URL structure as a real store.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/shopify/references/hydrogen.part2.md (reported line 417)May include surrounding context.

md
type CustomerPrivacyApiProps = {
/** The production shop checkout domain url. */
checkoutDomain: string;
/\*\* The storefront access token for the shop. _/
storefrontAccessToken: string;
/** Whether to load the Shopify privacy banner as configured in Shopify admin. Defaults to true. \*/
withPrivacyBanner?: boolean;

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/shopify/references/hydrogen.part2.md (reported line 419)May include surrounding context.

md
type CustomerPrivacyApiProps = {
/** The production shop checkout domain url. */
checkoutDomain: string;
/\*\* The storefront access token for the shop. _/
storefrontAccessToken: string;
/** Whether to load the Shopify privacy banner as configured in Shopify admin. Defaults to true. \*/
withPrivacyBanner?: boolean;

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/shopify/references/hydrogen.part4.md (reported line 285)May include surrounding context.

md
type CustomerPrivacyApiProps = {
/** The production shop checkout domain url. */
checkoutDomain: string;
/\*\* The storefront access token for the shop. _/
storefrontAccessToken: string;
/** Whether to load the Shopify privacy banner as configured in Shopify admin. Defaults to true. \*/
withPrivacyBanner?: boolean;

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/shopify/references/storefront-graphql.md (reported line 18)May include surrounding context.

md
## mock.shop: a store to build against before you have one

[mock.shop](https://mock.shop) is a public, auth-free Storefront GraphQL API backed by mock reference stores. Use mock.shop when the user has no store, no Storefront API access token, or wants realistic data to build against. Find the setup guide at [How to use mock.shop](https://shopify.dev/docs/storefronts/headless/mock-shop).

- `https://mock.shop/llms.txt` lists every store with a one-line summary and its API URL. Each store is a separate catalog on its own host, and `https://<store>.mock.shop/llms.txt` describes that store's catalog.
- Send Storefront API queries as `POST https://<store>.mock.shop/api` with a JSON body (`{"query": "..."}`) and `Content-Type: application/json`. No access token or other credentials are needed; never send credentials to mock.shop. The bare apex `https://mock.shop/api` serves the default store. mock.shop also answers the versioned endpoint shape, `https://<store>.mock.shop/api/<version>/graphql.json`, so clients can use the same URL structure as a real store.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/shopify/references/storefront-graphql.md (reported line 21)May include surrounding context.

md
## mock.shop: a store to build against before you have one

[mock.shop](https://mock.shop) is a public, auth-free Storefront GraphQL API backed by mock reference stores. Use mock.shop when the user has no store, no Storefront API access token, or wants realistic data to build against. Find the setup guide at [How to use mock.shop](https://shopify.dev/docs/storefronts/headless/mock-shop).

- `https://mock.shop/llms.txt` lists every store with a one-line summary and its API URL. Each store is a separate catalog on its own host, and `https://<store>.mock.shop/llms.txt` describes that store's catalog.
- Send Storefront API queries as `POST https://<store>.mock.shop/api` with a JSON body (`{"query": "..."}`) and `Content-Type: application/json`. No access token or other credentials are needed; never send credentials to mock.shop. The bare apex `https://mock.shop/api` serves the default store. mock.shop also answers the versioned endpoint shape, `https://<store>.mock.shop/api/<version>/graphql.json`, so clients can use the same URL structure as a real store.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/shopify/references/storefront-graphql.md (reported line 23)May include surrounding context.

md
## mock.shop: a store to build against before you have one

[mock.shop](https://mock.shop) is a public, auth-free Storefront GraphQL API backed by mock reference stores. Use mock.shop when the user has no store, no Storefront API access token, or wants realistic data to build against. Find the setup guide at [How to use mock.shop](https://shopify.dev/docs/storefronts/headless/mock-shop).

- `https://mock.shop/llms.txt` lists every store with a one-line summary and its API URL. Each store is a separate catalog on its own host, and `https://<store>.mock.shop/llms.txt` describes that store's catalog.
- Send Storefront API queries as `POST https://<store>.mock.shop/api` with a JSON body (`{"query": "..."}`) and `Content-Type: application/json`. No access token or other credentials are needed; never send credentials to mock.shop. The bare apex `https://mock.shop/api` serves the default store. mock.shop also answers the versioned endpoint shape, `https://<store>.mock.shop/api/<version>/graphql.json`, so clients can use the same URL structure as a real store.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
skills/shopify/scripts/_validate_components.mjs:44
Evidence
`)}r(st,"formatCliHelp");function at(){let e=[process.env.CLAUDE_SESSION_ID,process.env.CLAUDE_CODE_SESSION_ID,process.env.CURSOR_SESSION_ID,process.env.COPILOT...

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
skills/shopify/scripts/_validate_functions.mjs:12
Evidence
`));return e.line+=c.length-1,e.lineStart=o,p}if(l===92&&n.charCodeAt(s+1)===34&&n.charCodeAt(s+2)===34&&n.charCodeAt(s+3)===34){u+=n.slice(a,s),a=s+1,s+=4;cont...

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
skills/shopify/scripts/_validate_graphql.mjs:12
Evidence
`));return e.line+=c.length-1,e.lineStart=o,p}if(l===92&&n.charCodeAt(s+1)===34&&n.charCodeAt(s+2)===34&&n.charCodeAt(s+3)===34){u+=n.slice(a,s),a=s+1,s+=4;cont...

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
skills/shopify/scripts/_validate_theme.mjs:18
Evidence
`)}o(K,"formatCliHelp");function q(){let e=[process.env.CLAUDE_SESSION_ID,process.env.CLAUDE_CODE_SESSION_ID,process.env.CURSOR_SESSION_ID,process.env.COPILOT_S...

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
skills/shopify/scripts/log_feedback.mjs:2
Evidence
var le=Object.defineProperty;var n=(e,t)=>le(e,"name",{value:t,configurable:!0});import{createHash as Le}from"crypto";import{chmodSync as ke,closeSync as xe,lst...

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
skills/shopify/scripts/log_skill_use.mjs:3
Evidence
`)}o(R,"formatCliHelp");function C(){let e=[process.env.CLAUDE_SESSION_ID,process.env.CLAUDE_CODE_SESSION_ID,process.env.CURSOR_SESSION_ID,process.env.COPILOT_S...

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
skills/shopify/scripts/search_docs.mjs:2
Evidence
var le=Object.defineProperty;var r=(e,t)=>le(e,"name",{value:t,configurable:!0});var l=["use-shopify-cli","admin","shopifyql","storefront-graphql","partner","cu...

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
skills/ucp/scripts/log_feedback.mjs:2
Evidence
var le=Object.defineProperty;var n=(e,t)=>le(e,"name",{value:t,configurable:!0});import{createHash as Le}from"crypto";import{chmodSync as ke,closeSync as xe,lst...

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
skills/ucp/scripts/log_skill_use.mjs:3
Evidence
`)}o(N,"formatCliHelp");function R(){let e=[process.env.CLAUDE_SESSION_ID,process.env.CLAUDE_CODE_SESSION_ID,process.env.CURSOR_SESSION_ID,process.env.COPILOT_S...