Back to skill

Security audit

Clawringhouse - AI Shopping Concierge

Security checks across malware telemetry and agentic risk

Overview

This shopping skill is not clearly malicious, but it asks agents to use personal context and browser sessions to modify shopping carts while forcing affiliate tracking without enough user control.

Review before installing. Use this skill only if you are comfortable with shopping queries going to Clawringhouse, affiliate-tagged Amazon links, and an agent potentially using browser sessions. Require the agent to ask before reading memory/calendar context, opening a logged-in shopping site, adding or changing cart items, or using affiliate links/cookies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The README asserts 'No data harvesting' while instructing agents to send shopping queries to external API and website endpoints. Even if the operator does not retain data long-term, the infrastructure necessarily receives user inputs and related metadata, so the claim is misleading and can cause users or agents to disclose sensitive shopping intent without informed consent.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs the agent to inspect memory and calendar data and act on inferred personal needs for shopping and affiliate marketing without a clear user request or consent. This combines sensitive-context mining with commercial action, creating privacy, profiling, and manipulation risks beyond what is necessary for a shopping assistant.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The skill directs browser automation against the user's Amazon session and cart, including logged-in contexts, to add items and prepare purchases. Even if it stops short of checkout, modifying a user's account state is an account-impacting action that can cause unintended purchases, confusion, privacy leakage, and abuse of authenticated sessions.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill claims the goal is 'not to buy things' while earlier instructions direct cart manipulation and mandatory affiliate-tag insertion to secure attribution cookies and commissions. This mismatch is deceptive because it downplays commercial incentives and account-impacting behavior, undermining informed user consent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill encourages agents to call a third-party search API and prepare shopping cart links without clearly warning that user prompts will be sent off-platform and that shopping actions may create affiliate-tracked links or modify a cart context. In an agent setting, this can lead to silent disclosure of sensitive preferences or unintended commercial side effects without explicit user approval.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill encourages the agent to inspect private context sources and proactively act on them without a prominent warning that personal data will be used for commercial recommendations and possible cart preparation. Users are not clearly informed about privacy implications or downstream account effects, so consent is not meaningful.

Missing User Warnings

High
Confidence
99% confidence
Finding
The skill omits a clear warning that browser automation may add items to a logged-in Amazon cart, which changes account state and can influence later purchasing decisions. Because users are not plainly told this may happen before the automation steps are described, the behavior is risky and insufficiently transparent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill mandates affiliate tags in all links but does not clearly disclose that clicks set tracking cookies and generate commissions for the operator. This creates a transparency and consent problem, especially because the monetization requirement is presented as a rule for the agent rather than a user-visible commercial disclosure.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to mine memory, calendar, and partner preference data to infer needs and initiate outreach without being asked. This increases the chance of exposing sensitive relationship, household, or behavioral information in ways the user did not expect or authorize.

Ssd 3

Medium
Confidence
91% confidence
Finding
The example outreach messages encourage unsolicited disclosure of sensitive remembered details such as a partner's preferences or a pet's health-related condition. Even if intended to be helpful, broadcasting inferred private information in proactive messages can violate expectations and reveal more than is necessary for a recommendation.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
# Clawringhouse Skill — AI Shopping Concierge

**For agents who want to make their humans look thoughtful without asking them to shop.**

## Philosophy
Confidence
89% confidence
Finding
without asking

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.