Dropshipping Product Research

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward dropshipping research skill with no scripts, hidden behavior, credential handling, or automatic actions in the reviewed artifact.

Safe to consider for advisory e-commerce research. Before running the optional global npx install command, make sure you trust the referenced GitHub repository and package workflow, because that external repository content is outside this single artifact review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal