Back to skill

Security audit

clawec-1688-product-search

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward 1688 product-search helper that uses a user-provided ClawEC API key and sends search terms to ClawEC.

Install this only if you are comfortable using a ClawEC API key and sending product search keywords or sourcing research terms to ClawEC. For sensitive business research, invoke it explicitly for 1688 searches and avoid ambiguous general product-research prompts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation description is broad enough to trigger on generic product-research or sourcing requests, which can cause the agent to invoke this external skill in situations where the user did not clearly request 1688/Clawec lookups. That increases the chance of unnecessary third-party data disclosure and unintended API use, especially if user prompts contain sensitive business research context.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.