Skip to content
09.10.2026Shopify · 5 min read

Shopify app security check: scan vs agent.

Shopify CLI 4.9.0 adds an app security check that splits audits into a local scan and agent review prompts, so gate CI on the scan and read the agent output.

A Shopify app security check now ships inside the CLI. Version 4.9.0, released on October 8, 2026, adds shopify app security, a set of commands that splits an audit into two tracks: a deterministic scan that runs on your machine, and a list of questions handed to the coding agent already sitting in your editor. For any merchant running a custom app on Shopify Plus, that split is the most useful thing to happen to app review this year, as long as you understand what each track can and cannot promise.

What Shopify CLI 4.9.0 added

Shopify CLI 4.9.0 adds five commands under shopify app security: check, record, review, instructions and clean. The 4.9.0 release notes describe the flow. check runs fixed rules and writes two files into .shopify/app-security/: the deterministic findings, and a set of checks for your agent to investigate. The agent explores the code, then record stores its findings and review merges both tracks into one report.

The agent prompts live in the open, in the CLI's security check directory. There are 35 of them: 25 rated high severity, 9 medium and 1 low. They cover the bugs that actually hurt Shopify apps: missing tenant isolation between shops, unverified app proxy signatures, missing compliance webhooks, offline tokens stored in metafields, open redirects, SSRF, SQL injection and unsafe Liquid rendering in theme extensions.

Two design choices stand out in the source. The engine never calls a model itself, so there is no API key and no network call; your agent does the reasoning with the repository access it already has. And a new --blocking flag sets the minimum severity that fails the run. It defaults to none, so nothing breaks a build until you opt in.

Deterministic scan vs agent review

The deterministic scan answers questions of fact; the agent review answers questions of judgement. Shopify's own engine comments draw the line exactly there. Whether an API version is end of life is a lookup, and a static rule gets it right every time. Whether a database query is scoped to the shop making the request is not: answering it means following inherited controllers, default scopes and background jobs across files.

That distinction decides how much weight each result deserves. A deterministic finding is reproducible. Run it twice, get the same answer, gate a merge on it. An agent finding is a lead. It can be sharp, and on tenant isolation it will catch things no regex ever will, but it can also miss a path or flag a safe one, and two runs can disagree. Treat the first track as a test and the second as a reviewer's comment.

The trap is reading a clean combined report as a security sign off. A clean deterministic scan means the known patterns are absent. A clean agent pass means one model, on one day, did not find a problem in the files it chose to read. Neither is a penetration test, and neither looks at your hosting, your secrets manager or the people with admin access to the store.

Why it matters for Shopify Plus merchants

Custom apps are the least reviewed code in most Shopify Plus stacks. Public apps go through Shopify's app review before listing. A custom app built for one merchant, often by a freelancer or a small agency years ago, usually goes through nothing. It still holds an offline access token with write scopes on orders, customers and discounts.

The tenant isolation prompt is a good example of why this matters even for single store apps. Plenty of custom apps started as one merchant's tool and later got installed on a second store for a sister brand or a new region. The code was never written to separate shops, and a query that filters on an order ID taken from the request can now read the other brand's data. That is precisely the cross shop leak this check hunts for.

The rest of the 4.9.0 release points the same way. Every command now accepts --no-input, a --json-schema flag describes command output, errors print as JSON with --json, and interactive prompts moved to stderr. Shopify is designing the CLI to be driven by agents as much as by people, which matches what we wrote about the Shopify AI Toolkit.

What we would change this quarter

Put the deterministic scan in CI now and keep the agent review as a scheduled human step. On the Shopify Plus builds we run, that becomes four concrete moves.

  1. Upgrade to CLI 4.9.0 and run shopify app security check --list-files first. It prints the scan scope and stops. If your backend lives outside the app folder, add it with --include-dir, or the scan will quietly skip the code that matters most.
  2. Add the check to the pull request pipeline with --blocking high. Start strict on high only; medium findings go to the backlog until the noise level is known.
  3. Run the agent track before each release, not on every commit. Have an engineer read the recorded findings and either fix them or write down why they are safe. An unread agent report is worse than none, because it creates the impression of review.
  4. Inventory every custom app with write scopes and run the check on each, including the ones nobody has touched since 2023. Those are the likeliest to fail the end of life API version and compliance webhook rules.

Leave the results out of version control. The CLI writes its own .gitignore inside .shopify/ for that reason, and nobody should force the files in to share them: findings describe your weaknesses in plain language. Share a summary in the ticket instead. If you are wiring agents into wider engineering workflows, our AI-native practice covers how we keep humans on the judgement calls.

Where to dig deeper

Same topics, adjacent entries
J–00906.2026 · 5 min

Mage-OS beat Shopify with a data ownership pitch

J–04509.2026 · 4 min

Polaris CDN semver: pinned vs stable

J–06710.2026 · 5 min

JPEG XL vs AVIF: Chrome 155 and product images

J–00105.2026 · 2 min

We're starting a journal

Want this done right on your store?

We engineer premium e-commerce end-to-end, Magento Hyvä, Shopify Plus, mobile and automation. A two-week store audit turns ideas like the one above into real numbers and a prioritised roadmap for your store.