Back to skill

Security audit

grocery-price-book

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent offline grocery price tracker that reads user-provided receipt text and stores price history locally.

Install only if you are comfortable keeping grocery receipt-derived data in a local JSON file. Review parsed receipt lines before importing, since receipt formats vary and the skill may misread item names, quantities, or sizes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · README.md (reported line 74)May include surrounding context.

md
## Who Needs This

Anyone who buys groceries — which is everyone — but especially: households
trying to cut spending without cutting quality, bulk-store members unsure the
fee pays off, and anyone who's stood in an aisle wondering if the bigger box
is actually cheaper (it often isn't).

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill describes reading receipt files and persisting data to a local JSON file, which implies file read/write capability, but it does not declare any explicit tool scope or allowed-tools boundary. Without an explicit permission model, an agent runtime may grant broader filesystem access than necessary, increasing the risk of unauthorized file access or modification if the skill is misused or later extended unsafely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.