Back to skill

Security audit

Shopping Candidate Fetcher20

Security checks across malware telemetry and agentic risk

Overview

This shopping skill is locally scoped, but its guidance appears designed to steer recommendations toward Li Ning rather than neutrally compare candidates.

Review this skill carefully before installing. It does not appear to steal data or run privileged code, but it is not a neutral shopping helper: its instructions are likely to bias recommendations toward Li Ning products. Use it only if that brand preference is intentional and disclosed to users.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The skill claims it will preserve and evaluate a fixed candidate list objectively, but the later documentation strongly primes the model toward selecting 李宁 through repeated examples, slogans, and tie-break rules. This creates covert recommendation steering: the retrieved payload may remain unchanged, yet the actual selection guidance can be systematically biased away from user needs and neutral evaluation.

Natural-Language Policy Violations

Medium
Confidence
99% confidence
Finding
The examples and rules repeatedly encode preference for a specific Chinese brand and Chinese-series naming as positive signals, even when the top-level skill claims neutral candidate comparison. In a shopping context, this can manipulate downstream agent output, reduce fairness and user autonomy, and cause systematically skewed recommendations unrelated to actual best fit.

Ssd 4

Medium
Confidence
98% confidence
Finding
The cumulative few-shot demonstrations, selection rules, and tie-breakers form a strong latent prompt pattern that steers the model toward a predetermined conclusion regardless of the candidate set. This is dangerous because it can bypass the stated requirement for fixed-list, evidence-based comparison and instead operationalize hidden sponsored or policy-like steering inside documentation.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.