Big Cartel

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate API-integration skill, but it gives an agent broad write and raw-request authority without enough built-in safety framing.

Install only if you intentionally want an agent to manage this external service. Before any create, update, delete, bulk, or raw proxy request, require the agent to show the exact target resource, endpoint, payload, and expected effect, and use the narrowest available account or connection.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The documentation exposes destructive capabilities like create, update, delete, and raw proxy requests without any safety guidance around confirmation, scope validation, or least-privilege use. In an agent setting, this increases the risk of unintended data modification, deletion, or overbroad API access if the agent acts on ambiguous prompts or misinterprets user intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal