Instacart

Security checks across malware telemetry and agentic risk

Overview

This skill transparently automates Instacart shopping and uses sensitive login/cart capabilities, but they are disclosed, purpose-aligned, and checkout remains under explicit user control.

Install only if you are comfortable letting the agent control an authenticated Instacart browser session, read the listed Instacart environment settings, and modify your cart. Leave INSTACART_CODE_EMAIL unset if you do not want automated mailbox-based verification-code retrieval, and review the final cart, fees, tip, address, and payment method before approving checkout.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill directs the agent to read local environment files for credentials and to access external email tooling to obtain one-time login codes. That expands the skill from grocery ordering into local secret access and inbox interaction, which increases the attack surface and can expose sensitive data beyond what is strictly necessary for the task.

Context-Inappropriate Capability

Low
Confidence
83% confidence
Finding
The browser recovery section authorizes local process control commands unrelated to shopping itself, including stopping and starting local services. Even if intended for reliability, this grants operational control over the host environment and could be abused or could disrupt other sessions/services if the agent misfires.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal