Ecommerce Product Research

Security checks across malware telemetry and agentic risk

Overview

The skill's requirements and instructions align with its stated purpose (PipiAds-based ecommerce research); the only noteworthy risk is the npm global install of a third-party package which should be audited before use.

This skill appears coherent for PipiAds-based ecommerce research, but take these precautions before installing or using it: 1) Audit the npm package (pipiads-mcp-server@1.0.3) — inspect its repository, maintainers, and recent release notes; avoid installing global packages unless you trust them. 2) Consider installing the helper in an isolated environment (container or dedicated VM) rather than your primary system. 3) Use a dedicated PIPIADS_API_KEY with limited scope/monitoring and check billing/credit usage (the skill notes API calls consume credits). 4) Verify the pipiads/pipispy sites and the npm package provenance if you need higher assurance. 5) Be aware the skill can invoke the helper server with your API key, so treat that key as sensitive and rotate/revoke if compromised.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal