Back to skill

Security audit

price-tracker

Security checks for vulnerabilities and agentic risk

Overview

The skill discloses its external API use, but it presents randomly generated price history as real historical data for money-related decisions.

Review before installing. Use it only if you are comfortable sending product queries and search-derived results to SkillBoss, and do not rely on its historical price reports, trend analysis, or predictions for purchase/resale decisions unless the publisher replaces the mock history with verifiable data or clearly labels it as simulation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/track_product.py:45
Finding

Untrusted search content is embedded directly into an LLM instruction

Content
View full analysis
List[Dict]: """Search product prices via SkillBoss API Hub (web search + LLM extraction).""" # Step 1: web search for product listing on platform search_result = pilot({ "type": "search", "inputs": {"query": f"site:{platform}.com {keyword} price buy"}, "prefer": "balanced", }) search_data = search_result["result"] # Step 2: LLM extracts structured price data from search results extract_result = pilot({ "type": "chat", "inputs": { "messages": [ { "role": "user", "content": ( f"From these search results, extract the current price for '{keyword}' on {platform}. " f"Return ONLY a valid JSON object with these fields: " f'{{\"title\": string, \"price\": number, \"seller\": string, \"rating\": number, \"condition\": string}}. ' f"Search results: {str(search_data)[:3000]}" ), } ] }, "prefer": "balanced", }) ``` ### Technical Analysis Search-result content controlled by marketplace pages, sellers, or other indexed third parties is concatenated directly into the same LLM message as the trusted extraction instruction. There is no strong separation between instructions and untrusted data. A malicious listing can contain prompt-like text directing the model to ignore the extraction request and return attacker-selected values. The subsequent regular-expression and JSON parsing logic verifies only that the response resembles a JSON object; it does not verify that the price, seller, rating, condition, or title is supported by ...[truncated 1348 chars]
Remediation
View remediation

other

Warning
Location
scripts/price_history.py:18
Finding

Synthetic random prices are presented as genuine historical data

Content
View full analysis
List[Dict]: """Generate mock historical price data.""" history = [] for i in range(days): date = (datetime.now() - timedelta(days=days - i)).strftime("%Y-%m-%d") # Simulate price volatility (±15%) volatility = random.uniform(-0.15, 0.15) price = base_price * (1 + volatility) history.append( { "date": date, "price": round(price, 2), "low": round(price * 0.95, 2), "high": round(price * 1.05, 2), } ) return history ``` The synthetic generator is used as the source of the reported history: ```python def get_price_history(product: str, platform: str, days: int) -> List[Dict]: """Get historical price data for a product.""" # Get current price via SkillBoss API Hub current = search_product(product, platform) if not current: return [] base_price = current[0]["price"] # Generate history history = generate_mock_history(base_price, days) return history ``` ### Technical Analysis The historical-price command retrieves only one current estimated price. It then creates every past observation by applying random volatility to that current value. These generated observations are assigned historical dates and are used to calculate trends, averages, volatility, price ranges, and predictions. Although the internal function is named `generate_mock_history`, the user-facing report labels the output as a “Price History Report” and does not identify the observations as simulated. This contradicts the declared capability to retrieve and analyze actual historical price data. Because the genera ...[truncated 1391 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tainted flow: 'SKILLBOSS_API_KEY' from os.environ (line 19, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/track_product.py (reported line 32)May include surrounding context.

python
def pilot(body: dict) -> dict:
    """Call SkillBoss API Hub /v1/pilot — auto-routes to optimal model/service."""
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json=body,

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises substantial functionality for cross-retailer price tracking and arbitrage analysis, but the supplied code chunk contains only a comment and no operational code. Because the actual code does not implement the declared primary purpose or any of its core capabilities, this is a clear description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a real product-price monitoring/arbitrage tool. This code chunk does not actually fetch historical price data; it synthesizes price history using random fluctuations around a single current price returned by search_product. It can summarize and predict trends from that simulated data, but it does not identify arbitrage opportunities, calculate profit margins, or set alerts. While it references multiple platforms through imported platform definitions, its primary behavior in this chunk is mock historical reporting rather than authentic cross-platform monitoring or arbitrage analysis.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill's stated purpose is to monitor and track historical prices across marketplaces, but the implementation uses generated mock data instead of real historical observations. Because the skill is positioned for arbitrage and profit analysis, this mismatch is especially dangerous: users may trust the output for financial decisions, causing monetary loss and undermining integrity of the tool.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README describes the skill with broad trigger language such as monitoring prices, researching products, and identifying opportunities across major retailers, which can match many ordinary shopping or research prompts. In an agentic system, this increases the chance the skill is invoked in situations the user did not explicitly intend, causing unnecessary external data access, irrelevant actions, or leakage of shopping/research context to the skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope or permissions despite documenting capabilities that require environment access, file I/O, and network access. This weakens least-privilege controls and can cause the skill to be invoked with broader capabilities than users expect, especially since it reads API keys and writes reports/alerts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is broad enough to match many ordinary shopping, research, and pricing prompts, increasing the chance of over-invocation. Because the skill also uses network access and an API key, loose triggering can cause unnecessary external requests and unintended data transmission beyond what a user specifically intended.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The skill transmits data and an authentication credential context to an external third-party endpoint, which is a meaningful security/privacy concern even if expected for functionality. Users may send product queries, monitoring targets, and potentially business-sensitive arbitrage research to SkillBoss without sufficient disclosure of what leaves the environment.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

export SKILLBOSS_API_KEY=your_skillboss_api_key

text

All scripts authenticate through SkillBoss API Hub (`https://api.skillboss.co/v1/pilot`) using `SKILLBOSS_API_KEY`.

## Core Capabilities

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation encourages automated alerts, cron jobs, and writing alert/report files without clearly warning about persistent background execution and local artifact creation. This can surprise users, create unattended network activity, and leave potentially sensitive or noisy files on disk, especially in shared or production environments.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code presents itself as retrieving historical price data, but it actually generates randomized synthetic history from the current price. In a price-tracking/arbitrage skill, fabricated history can mislead users into making purchasing or resale decisions based on nonexistent trends, especially because the output is formatted as if it were real data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script emits historical tables, trend analysis, volatility, and predicted prices derived entirely from mock data without any user-facing warning. This creates a high risk of deceptive output because users are likely to interpret the data and predictions as real marketplace intelligence, particularly in the context of automated price monitoring and flipping opportunities.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/track_product.py (reported line 20)May include surrounding context.

python
# SkillBoss API Hub — unified AI & web capability router
SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
API_BASE = "https://api.skillboss.co/v1"

PLATFORMS = {
    "amazon": {"fee_rate": 0.15, "name": "Amazon"},

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This code transmits user-supplied queries and processed search-result content to an external API endpoint. In the context of a price-tracking skill, that external transmission is expected functionality, but it still matters because users may not realize their inputs and fetched content leave the local environment.

Content

Scanner excerpt · scripts/track_product.py (reported line 32)May include surrounding context.

python
def pilot(body: dict) -> dict:
    """Call SkillBoss API Hub /v1/pilot — auto-routes to optimal model/service."""
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json=body,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sends the user-supplied product query and scraped search-result content to a third-party API for search and LLM extraction without an explicit runtime disclosure or consent step. This creates a privacy and data-governance risk because user inputs and retrieved marketplace data are transmitted off-host to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code performs a file write when --output is provided, but the write path has no confirmation prompt or explicit user-facing disclosure at the point of action other than the argument name itself. For code files, file writes can be flagged when they lack visible warning or explanatory disclosure, and there is no comment or runtime notice indicating that the report will overwrite the target file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script reads a credential from the environment to authenticate outbound API calls. There is no user-facing notice in the CLI interface or output that the skill depends on and will use this sensitive credential during execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.