shopify-expert

Fail

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions and code for loading external resources from https://third-party.com/widget.js. Automated security analysis has flagged this URL as a malicious domain associated with botnet infrastructure.
  • Evidence: Found in references/performance-optimization.md within a section describing how to load third-party scripts.
  • [REMOTE_CODE_EXECUTION]: The skill demonstrates a pattern for dynamic JavaScript injection that executes remote code. This pattern, when directed toward the identified malicious URL, creates a critical execution vector for unauthorized code within the agent's environment.
  • Evidence: var script = document.createElement('script'); script.src = 'https://third-party.com/widget.js'; script.async = true; document.body.appendChild(script); in references/performance-optimization.md.
  • [DATA_EXFILTRATION]: Antivirus scanners have flagged the file references/performance-optimization.md as infected with a suspicious HTTP request pattern (MD:HttpRequest-inf [Susp]). This infection, combined with the presence of a botnet-linked URL, poses a severe risk of sensitive data (such as API keys or customer records) being harvested and transmitted to external attackers.
  • [PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection because it ingests untrusted theme data and Shopify configurations without defining boundary markers or sanitization protocols.
  • Ingestion points: shopify theme pull operations and manual theme file reviews.
  • Boundary markers: Absent; instructions do not advise the agent to ignore embedded instructions in data.
  • Capability inventory: High-privilege actions including shopify theme push, shopify app deploy, and npm run deploy.
  • Sanitization: No validation steps are prescribed for data ingested from remote stores before it is used to influence further operations.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — shopify-expert