elm

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly transparent and consent-gated, but its listing-level description understates that it can use a logged-in Ele.me account and add items to your cart.

Only install or use this if you are comfortable letting the agent work inside your logged-in Ele.me session to prepare a cart. Do not provide passwords or verification codes, and always review the address, items, discounts, fees, total, and merchant before paying.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI09: Human-Agent Trust Exploitation
Medium
What this means

A user may install or invoke it expecting advice only, then discover it can operate inside their logged-in Ele.me account.

Why it was flagged

This user-facing description suggests public-information analysis, while the provided SKILL.md and README describe using an authenticated Ele.me session, reading account-visible data, and adding items to cart.

Skill content
Description: Help users make better Eleme ordering decisions from public merchant and promotion information.
Recommendation

Update the registry/listing description and capability metadata to clearly state authenticated-session use, saved address/coupon/cart access, add-to-cart behavior, and the no-payment boundary.

#
ASI03: Identity and Privilege Abuse
Medium
What this means

The agent may see account-specific addresses, coupons, red packets, and cart details while helping prepare an order.

Why it was flagged

The skill uses a user's authenticated Ele.me account context and personal delivery/account data. This is purpose-aligned for ordering assistance and is consent-gated, but users should notice the privilege involved.

Skill content
It may access the user's Ele.me account, saved addresses, account-visible coupons or red packets, and cart state only after explicit user consent
Recommendation

Use it only when you intend to let the agent work in your Ele.me session; do not share login secrets, and confirm the selected address and account context.

#
ASI02: Tool Misuse and Exploitation
Medium
What this means

Your cart may be changed, although the skill says you must still review and pay yourself.

Why it was flagged

Adding items to cart mutates account state, but the instructions require explicit consent and stop before payment or irreversible order submission.

Skill content
With explicit consent, add the chosen items to cart and select the best visible discount path. Stop at cart or pre-payment review.
Recommendation

Review the cart, merchant, items, delivery address, discounts, fees, and total before paying.