Mercado Libre

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a Mercado Libre helper with a broad activation note, but the supplied evidence does not show hidden, destructive, or unrelated behavior.

Install only if you want Mercado Libre-related assistance. Before letting it act on seller/account data, confirm what actions it can perform and require explicit approval for listing, order, pricing, or account changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The setup allows the skill to be 'always on for Mercado Libre requests' but does not define explicit trigger boundaries, scope, or disambiguation rules. This can cause the agent to activate on loosely related commerce or marketplace queries, increasing the chance of unintended behavior, inappropriate persistence of context, or execution of Mercado Libre-specific workflows when the user did not clearly request them.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal