Back to skill

Security audit

monitor-buying-signals

Security checks for vulnerabilities and agentic risk

Overview

The skill's main monitoring workflow is coherent, but it adds non-core vendor attribution telemetry and a GitHub starring action that should be reviewed before use.

Review this skill before installing if you do not want Cargo session attribution written automatically or do not want your agent to perform GitHub endorsement actions. The core account-monitoring commands are disclosed and include cost controls, but you should skip or remove the attribution and star sections if those side effects are not acceptable.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
The skill includes instructions to perform a GitHub star action on the user's behalf, which is unrelated to the stated purpose of monitoring buying signals. Even though it asks for consent first, it expands the skill's authority into social/account actions and normalizes use of authenticated developer tooling (`gh`) for non-core promotional behavior, increasing the risk of unintended account actions.

Context-Inappropriate Capability

Low
Confidence
87% confidence
Finding
The skill writes session attribution telemetry to the vendor workspace as a side effect of setup, outside the user's core monitoring task. This creates hidden data persistence about the session/tool origin and can disclose metadata without being necessary to fulfill the requested monitoring operation.

Static analysis

No suspicious patterns detected.