全网比价助手

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward shopping price-comparison skill, with expected external searches but some privacy and activation-scope caveats.

Install only if you are comfortable having product names or shopping links used for searches across external commerce platforms. Avoid submitting private account pages, order links, or URLs with sensitive tracking parameters; use plain product names where possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad everyday phrases such as “比价”, “哪里最便宜”, and “最低价”, which can cause accidental invocation during normal shopping conversations. This increases the chance that user queries or links are sent into cross-platform search and link-processing flows without clear user intent, creating avoidable privacy and UX risk.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill describes accepting product names or links and performing cross-platform searches, but it does not warn users that submitted links, product identifiers, or query terms may be transmitted to third-party platforms or affiliate services. In this context, silent external transmission is a real privacy and consent issue because the core workflow depends on querying multiple external services and potentially handling tracking-bearing commerce links.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal