Competitor Watch Pro

PassAudited by VirusTotal on May 17, 2026.

Findings (1)

The skill bundle directs the AI agent to interact with an external API hosted on a free ngrok tunnel (extant-torrie-nonrepealable.ngrok-free.dev), which is a common indicator of ephemeral or malicious infrastructure used to bypass security controls. There is a notable contradiction in SKILL.md: the 'Requirements' section claims no API keys are needed, yet the 'API' section instructs the agent to include an 'api_key' in POST requests, potentially leading to credential harvesting or unauthorized data tracking. While the network activity is plausibly related to the stated purpose of competitor research, the use of ngrok for a 'Pro' service is highly irregular and suggests a risk of data exfiltration.