Back to skill

Security audit

Ecommerce

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only e-commerce automation skill whose sensitive data and external integration risks are mostly disclosed, but users should review scope before connecting real stores.

Before installing, confirm what customer fields, order data, pricing permissions, and alert payloads the skill will access or send to external services. Avoid installing the optional full ecosystem bundle unless you have separately reviewed those skills and want broader multi-agent behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill describes customer segmentation, churn prediction, competitor scraping, and multi-channel alerts, but it does not clearly warn users that it processes privacy-sensitive customer data and may transmit data or notifications to external systems such as Slack, Telegram, webhooks, and APIs. In an e-commerce context, this omission can lead operators to enable the skill without understanding data handling scope, creating privacy, compliance, and unintended data disclosure risks.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.