Skills

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed WooCommerce product importer that uses a Yundian+ API key and remote API to queue imports, with no evidence of hidden or unrelated behavior.

Install only if you trust Yundian+ with your product import data and intend to let an agent queue WooCommerce imports. Keep the API key private, verify the API URL is the intended HTTPS endpoint, and explicitly confirm the source store, target store, and product scope before bulk or all-products imports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill requires an API key in environment variables and communicates with a remote service, but it does not explicitly declare permissions despite having env and network capabilities. This reduces transparency for users and platform policy enforcement, making it easier for a skill to access secrets and send data off-host without clear consent boundaries.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This skill performs state-changing operations against a WooCommerce store by creating/importing products, but the description and usage guidance do not prominently warn users that running it will modify the target store. Lack of an explicit mutation warning can lead to unintended product creation, catalog corruption, or mass imports initiated without informed user approval.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal