Back to skill

Security audit

Price Monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward price-monitoring helper that uses browser automation and local CSV logging, with some overbroad wording but no hidden or destructive behavior found.

Install only if you are comfortable with the agent visiting the product or competitor URLs you provide and saving price history locally. Treat email, Discord, cron scheduling, proxies, or user-agent rotation as manual additions that need separate review before use, especially for business-sensitive monitoring.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
86% confidence
Finding

The code substantially supports one part of the description: e-commerce price monitoring via browser automation, with price history logging and threshold-based alert messages. However, several declared capabilities are not present in the supplied code chunk. It does not monitor inventory/stock status, does not detect arbitrary page content changes beyond prices, and contains no scheduling functionality. Its alerting is limited to console messages rather than broader notification mechanisms implied by 'alert notifications.' Therefore the description overstates the implemented behavior enough to count as a mismatch, even though the core price-tracking purpose is aligned.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill documents shell usage, file reads, and file writes, but does not declare any explicit tool scope or permissions boundaries. In an agent environment, missing scope declarations can cause overbroad access and make it easier for the skill to be invoked with capabilities beyond what a user would expect, especially since it writes logs and runs scripts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation language is broad enough to match many generic web-monitoring tasks, which can cause the skill to be selected in contexts beyond narrow price tracking. Overbroad routing increases the chance that an agent will apply a shell- and file-capable skill to unintended requests, expanding attack surface and potentially exposing browsing, local files, or logged data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises email and Discord webhook alerts without warning that monitored data may be transmitted to third-party services. This can lead to unintended data exfiltration of URLs, pricing intelligence, or other monitored content, especially in enterprise or competitor-monitoring contexts where the collected data may be sensitive.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/monitor_prices.py (reported line 26)May include surrounding context.

python
"""Run agent-browser command and return output."""
    cmd = ["agent-browser"] + args
    try:
        result = subprocess.run(
            cmd,
            capture_output=True,
            text=True,

Static analysis

No suspicious patterns detected.