Back to skill

Security audit

lingxiao-ops-diagnosis

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed e-commerce profit and operations diagnostic guide that points users to an external Lingxiao MCP service but does not hide code, persistence, or destructive behavior.

Install this only if you are comfortable using Lingxiao's external MCP service for entered product, fee, and store metrics. Review what data you provide, especially before using the login-based whole-store analytics links, but the submitted skill itself is a transparent guide rather than hidden executable code.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation description contains broad natural-language triggers such as '做运营诊断、分析店铺数据、算真实利润、查退货率高的原因' that overlap with common business-analysis requests. This can cause the skill to be invoked in situations beyond the author's intended scope, increasing the chance of unnecessary external MCP use, user confusion, or unintended data exposure during store analysis workflows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.