Back to skill

Security audit

price-predator

Security checks across malware telemetry and agentic risk

Overview

This skill is a local, manual price-tracking CLI whose file storage is expected for its purpose and does not show hidden network, credential, or destructive behavior.

Before installing, be aware that tracked products, prices, timestamps, sources, and optional URLs are saved locally in ~/.price_predator_db.json unless you pass --db. Use a separate database path for sensitive shopping lists or shared systems, and delete or edit the JSON file when you no longer want the history retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
87% confidence
Finding
The markdown states that product data is stored persistently in ~/.price_predator_db.json but does not warn users that their tracked products, prices, timestamps, and possibly URLs will remain on disk. This can create an avoidable privacy and operational risk, especially on shared systems or when users assume the tool is ephemeral.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.