shopify

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The script scripts/shopify_init.py is designed to search for and read .env files from multiple locations, including parent directories and the .claude/ directory. This constitutes a data exposure risk as these files typically contain sensitive API keys, secrets, or credentials that should not be automatically harvested by a utility script.
  • Evidence: scripts/shopify_init.py (lines 86-103) in the get_env_paths method and (lines 49-65) in the load_env_file method.
  • [COMMAND_EXECUTION]: The script scripts/shopify_init.py utilizes subprocess.run to execute external shell commands. While currently used to check the version of the Shopify CLI, the inclusion of subprocess execution in a setup script represents an attack surface for command injection if modified or if environment variables are manipulated.
  • Evidence: scripts/shopify_init.py (line 185): subprocess.run(['shopify', 'version'], ...).
  • [OBFUSCATION]: The file scripts/.coverage is provided in a binary SQLite format. Including binary data within a skill repository is a known obfuscation technique used to bypass text-based static analysis and can be used to hide malicious payloads or secondary instructions.
  • Evidence: scripts/.coverage file content is a binary SQLite database.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — shopify