Back to skill

Security audit

卖家之家(跨境电商)活动查询与发布

Security checks across malware telemetry and agentic risk

Overview

The skill has a legitimate MJZJ activity workflow, but it can upload files and publish business activities with an API key under broad triggers without a required final confirmation step.

Install only if you intend to let an agent use the MJZJ activity API. Before any publish action, require the agent to show the exact title, organizer, city or address, times, images, registration fields, and destination account, then explicitly confirm the upload and publication. Keep MJZJ_API_KEY out of chat, logs, URLs, and shared output, and rotate it if it may have been exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill includes authenticated, state-changing operations to upload files and publish activities, but it does not instruct the agent to obtain explicit user confirmation immediately before performing those remote write actions. In an agent setting, this increases the risk of unintended or premature external modifications if the agent infers intent too broadly or proceeds with incomplete user review.

Missing User Warnings

Low
Confidence
78% confidence
Finding
The skill requires an API key for authenticated operations and instructs use of the Authorization header, but it does not include guidance to protect the credential from disclosure, misuse, or logging. In agent environments, absent credential-handling constraints can lead to accidental exposure in traces, error messages, or tool outputs.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.