shopify-expert
Fail
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions and code for loading external resources from
https://third-party.com/widget.js. Automated security analysis has flagged this URL as a malicious domain associated with botnet infrastructure. - Evidence: Found in
references/performance-optimization.mdwithin a section describing how to load third-party scripts. - [REMOTE_CODE_EXECUTION]: The skill demonstrates a pattern for dynamic JavaScript injection that executes remote code. This pattern, when directed toward the identified malicious URL, creates a critical execution vector for unauthorized code within the agent's environment.
- Evidence:
var script = document.createElement('script'); script.src = 'https://third-party.com/widget.js'; script.async = true; document.body.appendChild(script);inreferences/performance-optimization.md. - [DATA_EXFILTRATION]: Antivirus scanners have flagged the file
references/performance-optimization.mdas infected with a suspicious HTTP request pattern (MD:HttpRequest-inf [Susp]). This infection, combined with the presence of a botnet-linked URL, poses a severe risk of sensitive data (such as API keys or customer records) being harvested and transmitted to external attackers. - [PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection because it ingests untrusted theme data and Shopify configurations without defining boundary markers or sanitization protocols.
- Ingestion points:
shopify theme pulloperations and manual theme file reviews. - Boundary markers: Absent; instructions do not advise the agent to ignore embedded instructions in data.
- Capability inventory: High-privilege actions including
shopify theme push,shopify app deploy, andnpm run deploy. - Sanitization: No validation steps are prescribed for data ingested from remote stores before it is used to influence further operations.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata