Back to skill

Security audit

price-predator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local price-tracking command-line tool that stores user-entered product data in a disclosed JSON file and does not show hidden, network, or privilege-seeking behavior.

Install only if you are comfortable with product names, URLs, prices, and price history being saved locally in ~/.price_predator_db.json by default. Use --db for a separate database, and be aware that remove permanently deletes that product record from the local database.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill describes functionality that reads and writes a local JSON database, but it does not declare any tool scope or permissions metadata. This creates a transparency and governance gap: users and hosting platforms cannot easily assess that the skill persists data to disk, which can lead to unintended file access or persistence in environments where such behavior should be explicitly authorized.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The remove command deletes a tracked product from the JSON database and immediately saves the modified database, making the change persistent. There is no confirmation prompt or cautionary disclosure in this code path to warn the user that the operation is destructive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that it stores tracked product data in a local JSON file under ~/.price_predator_db.json, but it does not clearly warn users about persistent local storage, retention, or privacy implications. While the data is not highly sensitive by default, silent persistence can surprise users, leak shopping interests or URLs on shared systems, and leave residual data after use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.