Back to skill

Security audit

DHgate

Security checks across malware telemetry and agentic risk

Overview

This is a local, instruction-only DHgate shopping support skill with disclosed local notes and no evidence of hidden network, credential, or destructive behavior.

Install this if you want DHgate-specific sourcing and order help. Confirm when the agent may activate and what it may save under ~/dhgate/, and avoid sharing payment credentials, identity documents, tax records, or card details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation criteria are broad enough to trigger on common shopping, marketplace, and dispute conversations that may not actually require this skill. Over-broad invocation can cause unintended collection or use of user context, inappropriate proactive interventions, and higher chance of the skill operating outside the user's expectations.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to store user-related purchasing preferences, seller patterns, and dispute evidence plans, but it does not require a clear user-facing notice or consent flow for that persistence. In a commerce and dispute context, this data can reveal behavioral profiles, business activity, and potentially sensitive transactional context, creating privacy and trust risks if retained unexpectedly.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.