Commerce Bi Copilot
Security checks across malware telemetry and agentic risk
Overview
The skill is internally consistent with its stated purpose: it transforms user-provided ecommerce notes into briefings using local heuristics and does not request credentials, install anything, or call external services.
This skill appears to do what it claims: turn pasted KPI notes into operator-ready briefs using local heuristics. Before installing, review the handler.py source if you want maximum assurance (the code is included). Do not paste sensitive secrets or raw export files containing credentials or PII into prompts — the skill will process whatever text you provide. Note that the agent can call skills autonomously by default, but this skill does not request extra privileges or credentials, and it has no install-time downloads.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
