Security audit
lingxiao-product-selection
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed product-selection workflow that connects users to a specific external MCP service for market and profit checks, without hidden code or local system authority.
Install only if you are comfortable sending product/category, pricing, country, and related business inputs to the Lingxiao MCP service. Keep API keys in your MCP client's normal secret/header configuration and review any paid subscription terms before using the higher-tier tools.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
