Coupon Finder Cn

Security checks across malware telemetry and agentic risk

Overview

This coupon skill has a coherent shopping purpose, but it asks an agent to claim coupons and track account-specific coupon status without clear consent, account-access, or data-retention boundaries.

Review before installing. Use only if you are comfortable with a shopping assistant potentially acting on e-commerce accounts, and ask the publisher to clarify per-action confirmation, login/session handling, affiliate behavior, reminder storage, and how stored coupon history can be disabled or deleted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly advertises automatic coupon claiming, which implies taking actions on external e-commerce accounts. Without clear confirmation, consent, and account-action warnings, a user or agent could trigger unintended claims, account changes, or policy-violating automation on third-party platforms.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The example prompt '帮我领取这个商品的所有优惠券' normalizes a broad account-affecting operation without any warning or confirmation boundary. This increases the chance an agent will perform bulk coupon claims on behalf of the user across external services without granular consent or understanding of side effects.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal