Xianyu Auto Ops

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Xianyu listing helper with a small local CSV normalizer and no evidence of hidden data transfer or persistent privileges.

Reasonable to install for marketplace listing work. When using batch mode, provide only product/SKU CSVs you intend the agent to read, and review generated claims, pricing, warranties, and defect disclosures before posting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill instructs the agent to read local reference files and a normalization script (`references/ai-services-template.md`, `references/playbook.md`, `scripts/batch_csv_to_brief.py <file>`) while the metadata does not declare permissions. This creates an undeclared file-read capability and can lead to unexpected access to local files or user-provided paths, especially when a user supplies a CSV filename.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal