Back to skill

Security audit

Supermarket Offer Watcher

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed grocery deal watcher that stores a local watchlist and can run user-configured web searches on a schedule, with privacy considerations but no hidden or destructive behavior found.

Install only if you are comfortable storing a local grocery watchlist that may include your home area and shopping preferences, and with scheduled checks sending product and location-based queries to external search/fetch services. Use a coarse location when possible, review or delete `/data/workspace/data/supermarkt-watchlist.json` when no longer needed, and only create the cron job if you actually want recurring checks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill advertises automated nearby deal checking and alerts, but the described implementation mainly stores configuration and provides workflow guidance rather than actual enforced behavior. This mismatch can mislead users about what data is processed, what automation really occurs, and whether notifications or external lookups are actually happening, undermining informed consent and safe deployment decisions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill describes reading and writing a persistent local data file but does not declare any tool scope or permissions boundary. That creates an authorization gap: an agent may use file capabilities without explicit user-visible scoping, which is risky for a skill handling location and shopping-preference data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill stores home location, radius, timezone, and product preferences in a local file, but it does not warn users that this creates a persistent record of potentially sensitive behavioral and location data. In a personal-shopping context, that data can reveal where a user lives and what they regularly buy, increasing privacy risk if the workspace is shared or later accessed by other tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs recurring web searches using product names and location-derived queries, but it does not disclose that user-derived location and shopping-interest data will be sent to external search/fetch services. In this context, repeated scheduled lookups can create a persistent external data trail linking a user's approximate location with consumption habits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.