Commercehq

Security checks across malware telemetry and agentic risk

Overview

The skill appears intended for store management, but it exposes high-impact delete actions without clear confirmation or safety controls.

Review this skill carefully before installing. Use it only with store credentials limited to the operations you truly need, and require the agent to show the exact customer, product, or collection and get explicit approval before any update or delete action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill prominently lists destructive capabilities such as deleting customers, products, and collections without any guidance to require confirmation, check authorization, or warn about irreversible effects. In an agentic context, this increases the risk that a vague or misinterpreted user request could lead to unintended data loss or destructive actions against a live store.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal