Back to skill

Security audit

lingxiao-listing-build

Security checks across malware telemetry and agentic risk

Overview

This skill appears to help build and check TikTok Shop or Etsy listing drafts through a disclosed Lingxiao MCP service, with no hidden store access or destructive behavior found.

Before installing, understand that product details and listing text you provide may be sent to Lingxiao's MCP service. Use it for TikTok Shop or Etsy listing draft/check workflows, and review any paid copy-generation action because the artifact says it requires an account, confirmation, and quota use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description contains broad activation triggers such as '当用户要上架商品、批量生成链接、做 Listing、检查标题标签是否超限、把商品资料导入平台、优化 Etsy Listing 时使用', which can match many ordinary e-commerce requests without tightly constraining when the skill should be invoked. Over-broad routing increases the chance this skill is auto-selected in contexts where it is not appropriate, which can lead to unnecessary external MCP usage, unintended data disclosure to the linked service, or user confusion about the skill's scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.