Buy Me a Pie

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Buy Me a Pie list-management integration that uses account credentials to read and change shopping lists.

Install only if you are comfortable giving the skill your Buy Me a Pie login and PIN. Treat them like passwords, avoid passing them on shared command lines or logs, do not override the API base URL unless you trust it, and review share or delete commands before allowing them to run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation tells users to place sensitive credentials in environment variables without any warning about secure handling, storage, rotation, or leakage risks. While env vars are common, users may expose them through shell history, shared terminals, logs, process inspection, or misconfigured CI environments, leading to account compromise.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal