Back to skill

Security audit

PriceWatch - Cross-Platform Competitive Price Monitor

Security checks across malware telemetry and agentic risk

Overview

PriceWatch is a disclosed price-monitoring skill that stores data locally and only sends alerts externally when the user configures notification services.

Install only if you are comfortable with the skill scraping the product URLs you add and, when alerts are configured, sending product names, platforms, prices, percent changes, and recommendations to Slack or Telegram. Avoid using untrusted watchlists on sensitive corporate networks unless URL restrictions are added.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises Slack, Telegram, email, and custom webhook notifications but does not clearly warn that product URLs, pricing data, and alert contents will be transmitted to third-party services configured by the user. This can lead to unintended disclosure of commercially sensitive monitoring data, especially when users assume the tool is otherwise local because the document emphasizes local SQLite storage and 'no external database required.'

Missing User Warnings

Low
Confidence
80% confidence
Finding
The application performs HTTP requests to user-supplied product URLs with no validation of allowed destinations. In this context, that creates SSRF-like behavior: an attacker who can add watchlist entries can cause the host running the skill to make outbound requests to arbitrary internal or external endpoints, potentially reaching metadata services or internal-only systems.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.