Price
v1.0.0Track prices, analyze historical and total costs, detect manipulation, set alerts, and advise on optimal purchase timing for consumers and businesses.
⭐ 5· 772·2 current·2 all-time
byIván@ivangdavila
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Name/description align with the instructions: the SKILL.md describes price assessment, tracking, alerts, and manipulation detection. However the skill references specific third‑party data sources (Keepa, CamelCamelCamel, Google Flights, Wayback Machine) that in practice may require API keys or paid access; the manifest declares no required credentials or config for these services. Also it promises periodic monitoring/alerts but provides no install or scheduling mechanism.
Instruction Scope
Runtime instructions tell the agent to create and manage files under ~/price/ (watchlist, history, alerts, purchases) and to 'poll price periodically' and 'monitor across retailers'. As an instruction-only skill there is no code to perform polling or notification delivery; the SKILL.md gives the agent broad discretion to fetch prices and contact external sources. It also instructs logging of purchase decisions (sensitive financial data) without specifying retention, encryption, or access controls.
Install Mechanism
No install spec and no code files — lowest-risk delivery. Nothing will be written to disk by an installer. The only persistence implied is via files the agent is instructed to create under ~/price/.
Credentials
The skill declares no required environment variables or credentials (good for transparency) but references data sources and APIs that often need keys (e.g., Keepa). The lack of declared credentials is inconsistent with the stated reliance on such services; the skill leaves ambiguous whether it will scrape web pages, use public endpoints, or expect the platform to provide keys.
Persistence & Privilege
always is false and there is no request to modify other skills or system-wide settings. The only persistence is per‑user files in ~/price/, which is proportionate to a tracking/alerting tool, but users should be aware their purchase history and watchlists will be stored locally unless otherwise stated.
What to consider before installing
This skill appears to be a legitimate price-tracking assistant, but several things are unclear and worth confirming before installing:
- Data sources and credentials: The instructions list Keepa, CamelCamelCamel, Google Flights, etc. Some of these require API keys or paid plans. Ask the publisher how the skill will access those sources and whether you need to provide API keys (none are declared). If the skill scrapes pages, verify that behavior is acceptable.
- Background monitoring & notifications: The SKILL.md says it will 'poll price periodically' and 'notify when hit' but there is no install/spec for a background process or notification channel. Confirm how alerts are delivered (email, push, agent notifications) and whether the skill will run autonomously.
- Local storage & privacy: The skill will store watchlists, histories, alerts, and purchases under ~/price/. That may include sensitive transaction history. Confirm retention, where files are stored, and whether they are encrypted or exported/shared anywhere.
- Permissions you expect: Because the skill can fetch external pages and write to home directory, only install if you trust the agent to access the network and manage local files. If you require stricter guarantees (no scraping, only API usage with your credentials, or no persistent logging), request an updated skill manifest that declares required env vars and an explicit install/run model.
If the publisher can clarify how data sources are accessed, how alerts are delivered, and provide an option that requires you to supply any API keys explicitly, that would reduce ambiguity and should move this to 'benign'.Like a lobster shell, security has layers — review code before you run it.
latestvk97cqq8hxzrwhhbdzcg8ndwwex814k1f
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
💰 Clawdis
OSLinux · macOS · Windows
