Back to skill

Security audit

Etsy Seller

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Etsy advice skill with no evidence of hidden execution, data collection, or privileged access.

This appears safe to install as an Etsy-selling helper. Treat its search-ranking, fee, and marketplace best-practice claims as advice to verify against current Etsy documentation before making business decisions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill's 'When to Use This Skill' section is broad enough to match many ordinary e-commerce or writing-help requests, which can cause the skill to be invoked in situations where a generic assistant would be more appropriate. Over-broad activation increases the chance of unnecessary routing, misleading domain-specific advice, or over-trusting skill content in unrelated contexts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest description uses expansive language like 'use when an Etsy seller asks for help with their shop, listings, tags, descriptions, pricing, or wants to analyze competitors,' which creates ambiguous activation conditions. This can lead to over-triggering on common seller-assistance requests and broaden the skill's effective authority beyond narrowly scoped Etsy-specific support.

Static analysis

No suspicious patterns detected.