Mercadona Products API

PassAudited by VirusTotal on May 5, 2026.

Overview

Type: OpenClaw Skill Name: mercaapi Version: 1.0.0 The skill provides a well-documented interface for an unofficial Mercadona (supermarket) API, offering endpoints for product searches, nutritional data, and receipt processing. The code and instructions in SKILL.md are consistent with the stated purpose and do not contain any indicators of malicious intent, data exfiltration, or unauthorized execution. The API (mercaapi.sgn.space) appears to be a specialized utility for nutritional tracking.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If used for receipt scanning, receipt contents may be processed by the external API service and Gemini, not just locally by the user's agent.

Why it was flagged

Receipt files or receipt URLs may contain personal purchase details and are sent to an unofficial third-party API, with Gemini also involved in extraction; the artifact discloses this feature but does not describe retention or data boundaries.

Skill content
Unofficial REST API for Mercadona ... POST /api/ticket/ Upload a Mercadona receipt (image or PDF) ... The `/api/ticket/` endpoint uses AI (Gemini)
Recommendation

Only upload receipts you are comfortable sharing with the service; redact personal or payment details where possible, and ask the agent to confirm before sending receipt files or URLs.