Back to skill

Security audit

CN Ecommerce Compliance

Security checks across malware telemetry and agentic risk

Overview

This skill is a plain compliance checklist for cross-border ecommerce sellers, with no executable code or hidden system access.

Safe to install as a reference checklist. Treat the legal, tax, certification, and platform guidance as a starting point, verify current rules with official sources or qualified professionals, and review the two separately suggested related skills before installing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list contains broad terms such as 'VAT', '产品认证', and '平台规则' that are common in ordinary business, tax, and compliance discussions. This can cause the skill to activate outside its intended scope, increasing the chance of inappropriate routing, irrelevant compliance advice, or context collisions with other skills handling legal, tax, or marketplace topics.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.