Back to skill

Security audit

极鲸云 Temu 数据分析与市场调研

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Temu market-research integration that queries GeekBI and stores its own GeekBI login state, with no evidence of hidden or unrelated behavior.

Install only if you are comfortable sending Temu queries and any image-search inputs to GeekBI and allowing the skill to keep a GeekBI login token in your user config directory. Avoid passing private images or alternate service URLs unless you intend to share them with that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill instructs the agent to read internal reference files and invoke multiple local scripts that make external queries, but it declares no permissions. This creates a mismatch between documented behavior and the security model, increasing the risk of undeclared file access, shell execution, and network use occurring without explicit review or sandboxing expectations.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.