Back to skill

Security audit

shop-research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only shopping research helper that uses Portage to check products, stores, and the user's Portage history without making purchases.

Before installing, confirm you are comfortable installing the Portage CLI and letting it access your Portage configuration, optional retailer/search API keys, and Portage order/search history. Do not paste API keys into chat; set them only in Portage's own config as the skill instructs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: shop-research
description: Research products and stores for the user through the `portage` CLI without buying anything. Looks up what something costs, where to get it, whether it's in stock, what Portage knows about a store (whether it can be bought from automatically, what it supports, the business details and policy links it publishes, when the local index last saw it), and what the user ordered through Portage. It is read-only. It searches, checks stores and reads order history, and never creates a cart, a checkout or a payment. Use when the user asks how much something is, where they can get it, whether

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
bins:
        - portage
      config:
        - ~/.portage/.env
        - ~/.portage/config.json
    install:
      - kind: brew

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
bins:
        - portage
      config:
        - ~/.portage/.env
        - ~/.portage/config.json
    install:
      - kind: brew

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
bins:
        - portage
      config:
        - ~/.portage/.env
        - ~/.portage/config.json
    install:
      - kind: brew

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
bins:
        - portage
      config:
        - ~/.portage/.env
        - ~/.portage/config.json
    install:
      - kind: brew

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
bins:
        - portage
      config:
        - ~/.portage/.env
        - ~/.portage/config.json
    install:
      - kind: brew

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
bins:
        - portage
      config:
        - ~/.portage/.env
        - ~/.portage/config.json
    install:
      - kind: brew

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
bins:
        - portage
      config:
        - ~/.portage/.env
        - ~/.portage/config.json
    install:
      - kind: brew

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
bins:
        - portage
      config:
        - ~/.portage/.env
        - ~/.portage/config.json
    install:
      - kind: brew

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
description: "Walmart Affiliate API key, for Walmart offers in portage find. The user sets it in ~/.portage/.env themselves, never in chat; only portage reads it, and the agent never reads or prints its value."
      - name: EBAY_BROWSE_ACCESS_TOKEN
        required: false
        description: "eBay Browse API access token, for eBay Buy It Now offers in portage find. The user sets it in ~/.portage/.env themselves, never in chat; only portage reads it, and the agent never reads or prints its value."
      - name: EBAY_MARKETPLACE_ID
        required: false
        description: "eBay marketplace id to search; portage defaults to the US marketplace. The user sets it in ~/.portage/.env; only portage reads it, and the agent never reads or prints its value."

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
description: "Walmart Affiliate API key, for Walmart offers in portage find. The user sets it in ~/.portage/.env themselves, never in chat; only portage reads it, and the agent never reads or prints its value."
      - name: EBAY_BROWSE_ACCESS_TOKEN
        required: false
        description: "eBay Browse API access token, for eBay Buy It Now offers in portage find. The user sets it in ~/.portage/.env themselves, never in chat; only portage reads it, and the agent never reads or prints its value."
      - name: EBAY_MARKETPLACE_ID
        required: false
        description: "eBay marketplace id to search; portage defaults to the US marketplace. The user sets it in ~/.portage/.env; only portage reads it, and the agent never reads or prints its value."

Static analysis

No suspicious patterns detected.