Security audit
卖家之家(跨境电商)资讯搜索与发布
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed MJZJ article search and publishing helper that can use an API key to manage and publish account content.
Install this only if you trust MJZJ and want an agent to help manage or publish articles there. Keep MJZJ_API_KEY private, review author identity, tags, article HTML, images, and publish time before publishing, and avoid importing HTML or media from untrusted sources.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
