Rakuten返利助手

Security checks across malware telemetry and agentic risk

Overview

This is a simple Rakuten cashback lookup skill with no code, install hooks, credentials, persistence, or privileged access.

This appears safe to install as a low-risk instruction-only cashback helper. Users should still verify any cashback or coupon links before using them, and the publisher should consider narrowing the generic trigger phrases to avoid the skill appearing for unrelated shopping questions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list contains broad terms such as '美国返利' and '海外购物返利' that could match generic shopping or deal-seeking requests outside the user's intent to invoke this specific skill. Overbroad activation can cause unintended routing, confusing responses, and increased exposure of users to affiliate-style recommendations when they did not explicitly request Rakuten-related assistance.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal