Back to skill

Security audit

buy

Security checks for vulnerabilities and agentic risk

Overview

This shopping skill is mostly careful about user approval, but it includes a direct raw UCP/MCP purchase fallback outside the advertised Portage CLI path.

Install only if you are comfortable with an agent helping with purchases and handling checkout flows. Prefer using it through the Portage CLI, keep approval set to require explicit confirmation, avoid the raw UCP/MCP fallback unless you understand the store protocol, and do not provide card numbers or credentials in chat.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill's final fallback explicitly allows shopping by manually driving a store's UCP/MCP endpoint when the Portage CLI is unavailable, which expands behavior beyond the declared CLI-only contract. That bypass can sidestep CLI-enforced guardrails, version checks, approval flow consistency, and other protections the rest of the skill relies on, increasing the risk of unauthorized or less-auditable purchase actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Including direct store-driving capability over raw UCP/MCP broadens the skill from a Portage CLI wrapper into a more general purchasing agent. In this context, that is dangerous because the CLI is presented as the mechanism that constrains behavior, validates flows, and mediates checkout safety; a parallel direct path weakens those assumptions and may enable inconsistent enforcement of purchase safeguards.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.