costco
What this skill does
A CLI tool for retrieving Costco receipt history and related data from the Costco backend API, with support for local caching and analytics.
github/mvanhorn - Data Exfiltration - 1.9k stars
Threat analysis
Skill info
pkg:github/mvanhorn/printing-press-library@5a78746?skill=costcoAssessments (2)
Data Exfiltration
Data Exfiltration via local-llm-review
internal/cli/import.go
The 'import' command reads data from a JSONL file and sends it to an API endpoint via POST requests. This could potentially be used to exfiltrate sensitive data if the input file contains such data.Insecure Credential Handling
Insecure Credential Handling via local-llm-review
internal/cli/auth.go
The 'auth setup' command instructs users to set an environment variable 'COSTCO_ID_TOKEN' with their token. This is not a secure way to handle credentials as environment variables can be exposed in loBadge
Add the Anomity scan badge for costco to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of costco? Report an issue or request a rescan.




