Back to skill
Skillv1.0.0

VirusTotal security

Amazon Refund & Price Tracker Agent · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

BenignApr 30, 2026, 5:10 AM
Hash
f8ddff49f23bfb78b60acbf3f36396c67d40c4a4ac8d2db27e61d33ce8424bbd
Source
palm
Verdict
benign
Code Insight
Package: EasyBuy Agent Demo (xpi) Version: 0.1.0 Description: MV3 Agent demo: panel -> SW -> CS -> tool -> result -> panel The EasyBuy Agent Demo is a browser extension designed for automating tasks, particularly on Amazon, by integrating with an external AI model. It requests broad permissions, including `<all_urls>` and `scripting`, which grant it significant control over web content and browser actions. The core logic involves an AI generating a sequence of 'tool calls' (browser actions or predefined 'skills') based on user input. These tool calls are then executed by a background service worker and a content script. Crucially, the extension implements a robust user confirmation mechanism: every single browser action proposed by the AI requires explicit user approval via the side panel before it is executed. This mechanism, combined with a whitelist of allowed browser tools and hardcoded expansions for higher-level 'skills', acts as a strong safeguard against malicious or unintended actions. While the permissions are extensive, they are necessary for its stated purpose of browser automation, and the user remains in ultimate control of each step. The user's OpenAI API key is stored locally within the browser's storage, and generated artifacts like screenshots are stored in IndexedDB.
External report
View on VirusTotal