Back to skill

Security audit

BuyWise

Security checks across malware telemetry and agentic risk

Overview

BuyWise is a coherent shopping research skill that uses public web sources and local prompt-generating scripts, with no evidence of hidden persistence, credential access, destructive behavior, or exfiltration.

Install this if you want an assistant to browse public shopping and review sites for purchase advice. Be aware that product names or links you ask about may be sent to external shopping/search sites, confirm retailer prices before buying, and treat any CouponClaw follow-up as a separate action you should approve deliberately.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation guidance is broad enough to match many ordinary shopping questions such as 'what do you think of this?' and 'should I buy this?', which can cause the skill to trigger in situations where the user did not explicitly request cross-site browsing or product analysis. Because the skill is designed to navigate external sites and aggregate data, over-triggering increases the chance of unnecessary external access, irrelevant tool use, and unintended interception of general shopping conversations that may have been better handled by a different skill or by the base assistant.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list contains very generic shopping phrases such as 'should I buy', 'is it worth buying', and 'price comparison' that are common in ordinary conversation. This increases the chance the skill is invoked unintentionally, which can cause unsolicited handling of user shopping queries and unexpected disclosure of shopping intent or redirection into this skill when the user did not explicitly request it.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.