Back to skill

Security audit

Ai Shopping Assistant

Security checks across malware telemetry and agentic risk

Overview

This shopping assistant appears to do disclosed purchase research and local calculation without hidden payment, credential, persistence, or exfiltration behavior.

Install only if you are comfortable with a shopping assistant using public web research and, when you explicitly authorize it, reading task-relevant visible shopping information such as logged-in prices, coupons, regional stock, or reviews. Do not provide passwords, payment details, verification codes, or authorize checkout actions; the skill says those are outside its boundary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The code explicitly considers IP-derived location when resolving the user's effective location, which introduces use of network-derived geolocation data beyond what is clearly necessary from the skill description. In a shopping assistant, location can affect currency, availability, and shipping, but falling back to IP without clear consent or minimization creates privacy risk and may infer sensitive regional information unexpectedly.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.