Buy from Amazon — Search, Cart & Order for AI Agents

v1.2.4

Need to buy something from Amazon? Search and shop on Amazon.com — compare prices and ratings, add items to cart, and place real orders shipped to any US add...

12· 1.4k·3 current·3 all-time
byLucas Brown@lucasgeeksinthewood
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
medium confidence
Purpose & Capability
Name/description match the behavior: the skill proxies Amazon searches, builds carts, and requests order/payment links via buystuff.ai. No unrelated env vars, binaries, or installs are required.
Instruction Scope
SKILL.md instructs the agent to send shipping address, email, and optional agentId to https://buystuff.ai and to persist/send a session ID header. That is expected for a shopping proxy, but the agent will transmit PII (shipping address and email) to the third party — callers should be explicit about consent and verify the destination.
Install Mechanism
Instruction-only skill with no install spec or code files — lowest-risk footprint on the local system. Nothing is downloaded or executed locally by the skill itself.
Credentials
No credentials or secret environment variables are requested. The declared data flows (shipping address, email, optional agent ID) match the stated purpose. Note: PII is still sent to an external service and payment is handled off-site, so this is a privacy/trust decision rather than a technical mismatch.
Persistence & Privilege
always is false and the skill does not request system-wide or other-skill config changes. The skill requires session-state persistence (X-Session-ID) for carts, which is reasonable for this use-case.
Scan Findings in Context
[no-findings] expected: Regex scanner found nothing to analyze because this is an instruction-only skill (only SKILL.md). That is expected; absence of findings does not validate the third-party service or its privacy/fulfillment claims.
Assessment
This skill behaves like a shopping proxy that will transmit your shipping address and email to a third party (buystuff.ai) and send you a payment link to complete purchases. Before using it: 1) Verify buystuff.ai (website, contact/support, reviews, privacy and refund policy). 2) Test with a low-cost item to confirm the workflow and fulfillment. 3) Do not provide any saved payment credentials through this skill; you will pay via a link on the vendor's site — verify the URL in the email before entering payment data. 4) Ensure the agent asks for and receives explicit, unambiguous user approval before requesting a payment link (the SKILL.md requires this but it is not enforced programmatically). 5) Accept that you are trusting buystuff.ai to place the Amazon order and handle refunds; if you need stronger guarantees (use of your own Amazon account, direct payment methods, or avoiding third-party handling of PII), choose a different workflow.

Like a lobster shell, security has layers — review code before you run it.

agent-shoppingvk972fhs5s6fb6wc9ppwapzw7r981gnzhamazonvk972fhs5s6fb6wc9ppwapzw7r981gnzhamazon.comvk972fhs5s6fb6wc9ppwapzw7r981gnzhbuyvk972fhs5s6fb6wc9ppwapzw7r981gnzhbuystuffvk972fhs5s6fb6wc9ppwapzw7r981gnzhcartvk972fhs5s6fb6wc9ppwapzw7r981gnzhcommercevk972fhs5s6fb6wc9ppwapzw7r981gnzhdeliveryvk972fhs5s6fb6wc9ppwapzw7r981gnzhecommercevk972fhs5s6fb6wc9ppwapzw7r981gnzhgiftvk972fhs5s6fb6wc9ppwapzw7r981gnzhlatestvk972fhs5s6fb6wc9ppwapzw7r981gnzhonline-shoppingvk972fhs5s6fb6wc9ppwapzw7r981gnzhordervk972fhs5s6fb6wc9ppwapzw7r981gnzhproduct-searchvk972fhs5s6fb6wc9ppwapzw7r981gnzhpurchasevk972fhs5s6fb6wc9ppwapzw7r981gnzhshoppingvk972fhs5s6fb6wc9ppwapzw7r981gnzh

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments