Back to skill

Security audit

Price Gap Monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed marketplace price-checking guide that helps users compare visible prices and avoids hidden data claims or automatic business changes.

Before installing, understand that the skill can guide competitive pricing decisions and may use browser-visible marketplace pages or data you provide. Treat its recommendations as decision support, especially for margin-sensitive changes, and avoid logging into marketplaces unless you are comfortable with the agent viewing account-personalized pages during the task.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Hidden Instructions

High
Category
Prompt Injection
Content
## Mode A — Product-Level Output

### 1. Executive Summary
<!-- Max 5 lines. State: product, platforms checked, your current price, key finding, and one-line recommendation. -->

**Product:** [Product name / model]
**Platforms checked:** [List]
Confidence
70% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
## Solves

- **Blind pricing decisions**: Seller is setting or adjusting prices without checking what competitors actually charge on visible marketplaces.
- **Cross-platform price drift**: Same product listed at different prices across Amazon, Walmart, Temu, TikTok Shop — seller doesn't know where they're under or over.
- **Promo impact blindness**: Competitor ran a flash sale or coupon and the seller missed it, losing traffic without understanding why.
- **Category-level mispricing**: Seller positioned in a price band that doesn't match the visible market center, either leaving money on the table or pricing themselves out.
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
## Solves

- **Blind pricing decisions**: Seller is setting or adjusting prices without checking what competitors actually charge on visible marketplaces.
- **Cross-platform price drift**: Same product listed at different prices across Amazon, Walmart, Temu, TikTok Shop — seller doesn't know where they're under or over.
- **Promo impact blindness**: Competitor ran a flash sale or coupon and the seller missed it, losing traffic without understanding why.
- **Category-level mispricing**: Seller positioned in a price band that doesn't match the visible market center, either leaving money on the table or pricing themselves out.
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Static analysis

No suspicious patterns detected.