shopify
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The script
scripts/shopify_init.pyis designed to search for and read.envfiles from multiple locations, including parent directories and the.claude/directory. This constitutes a data exposure risk as these files typically contain sensitive API keys, secrets, or credentials that should not be automatically harvested by a utility script. - Evidence:
scripts/shopify_init.py(lines 86-103) in theget_env_pathsmethod and (lines 49-65) in theload_env_filemethod. - [COMMAND_EXECUTION]: The script
scripts/shopify_init.pyutilizessubprocess.runto execute external shell commands. While currently used to check the version of the Shopify CLI, the inclusion of subprocess execution in a setup script represents an attack surface for command injection if modified or if environment variables are manipulated. - Evidence:
scripts/shopify_init.py(line 185):subprocess.run(['shopify', 'version'], ...). - [OBFUSCATION]: The file
scripts/.coverageis provided in a binary SQLite format. Including binary data within a skill repository is a known obfuscation technique used to bypass text-based static analysis and can be used to hide malicious payloads or secondary instructions. - Evidence:
scripts/.coveragefile content is a binary SQLite database.
Audit Metadata