E-commerce find skills
PassAudited by VirusTotal on Mar 31, 2026.
Findings (1)
This skill acts as a package manager for the 'LinkFox' ecosystem, instructing the AI agent to execute shell commands (`linkfoxskill install`) to download and install external code into its workspace (e.g., `~.claude` or `~.openclawworkspace`). The SKILL.md file contains strong prompt instructions ('must trigger') to hijack the agent's tool selection for any e-commerce related queries. While aligned with its stated purpose, the capability to install and update arbitrary skill bundles from a remote market represents a significant attack surface for supply chain attacks and remote code execution.
