Back to skill

Security audit

E-commerce Revenue Pack

Security checks across malware telemetry and agentic risk

Overview

This is a benign e-commerce reporting skill with a disclosed local file-saving convention that users should confirm before use.

Safe to install for normal use. Before approving saved reports, confirm the exact folder and filename, and consider whether your Documents folder is backed up or shared because reports may contain commercially sensitive pricing and margin data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
93% confidence
Finding
The skill instructs the agent to save outputs to a fixed absolute path under the user's home directory. Even though it says to confirm before writing, the fixed-path behavior can still cause unintended writes, overwrite existing files, leak sensitive business data into a predictable location, or fail unsafely in environments where that path is inappropriate or shared. In this context the content is mostly business automation, which makes the issue less severe than an overt exfiltration or destructive command, but it is still a real filesystem-safety concern.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.