ShopBack返利助手

Security checks across malware telemetry and agentic risk

Overview

This is a small instruction-only ShopBack cashback helper with no code, install steps, credential access, or hidden system behavior.

This appears safe to install as a lightweight prompt/template skill. Treat cashback percentages, offers, and links it produces as unverified unless the agent checks an official ShopBack or merchant source at use time.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list contains broad phrases such as 'shopback', '东南亚返利', and '澳洲返利' that can match many generic shopping or cashback queries. This can cause unintended invocation, routing users into this skill when they did not explicitly request it, which increases the risk of user confusion, misdirected actions, or abuse if the skill later gains transactional capabilities.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal