ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      pfrederiksen

      Safety Report

      Shipment Tracker

      @pfrederiksen

      Track packages across carriers (USPS, UPS, FedEx, DHL, Amazon, OnTrac, LaserShip). Use when: user asks about package status, adds a tracking number, wants de...

      290Downloads
      0Installs
      1Stars
      3Versions
      Networking & DNS1,102

      Security Analysis

      high confidence
      Clean0.08 risk

      The skill does what it says: it reads a local shipments markdown file, tries HTTP tracking lookups, and—if needed—provides an optional cloud-based browser fallback; the behavior is disclosed and proportional to the stated purpose.

      Feb 23, 20263 files2 concerns
      Purpose & Capabilityok

      Name/description match the implementation: the script parses a shipments markdown file, detects carrier patterns, builds carrier tracking URLs, and performs HTTPS GETs to carrier pages. There are no unrelated permissions, binaries, or credentials requested.

      Instruction Scopenote

      Runtime instructions and the script are scoped to reading a single markdown file and making read-only HTTPS requests. However, the SKILL.md explicitly supplies an optional 'browser-use' command that sends tracking numbers and URLs to a cloud browser/LLM service for JS-heavy pages; that step transmits user shipment data outside the local machine and is a privacy decision the user must make.

      Install Mechanismok

      No install spec or external downloads are provided (instruction-only skill + included Python script). Nothing is written to disk by an installer; risk from installation is low. The optional dependency 'browser-use' is noted but not auto-installed by the skill.

      Credentialsnote

      The skill requests no environment variables or credentials, which is appropriate. One caveat: the optional browser-use flow relies on a third-party module/service that may require credentials or send data to external providers; those network interactions are not controlled via declared env vars in the skill metadata.

      Persistence & Privilegeok

      The skill does not request permanent presence (always:false), does not modify other skills or system configs, and performs only read operations on a specified file and outbound HTTPS GETs.

      Guidance

      This skill appears internally consistent with its description, but be mindful of privacy when following the browser-use fallback: the provided command sends tracking numbers, tracking URLs, and order details to a cloud browser/LLM service (explicitly noted by the author). If your shipments are sensitive, run the HTTP-only checks locally or perform manual browser checks. Before using the cloud fallback, review the 'browser_use' package and the cloud provider's privacy/retention policies, and confirm whether any API keys or credentials are required. If you enforce strict egress policies, run the script in an environment without outbound access or disallow the cloud browser step.

      Latest Release

      v1.1.1

      Privacy disclosure: document that browser-use fallback transmits tracking data to cloud services

      More by @pfrederiksen

      Email Intelligence

      2 stars

      Synology Backup

      2 stars

      Photo Captions

      2 stars

      Arccos Golf Performance Analyzer

      1 stars

      GHIN Golf Tracker

      1 stars

      OpenClaw Cost Tracker

      1 stars

      Published by @pfrederiksen on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]