Ecommerce Competitor Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a text-only ecommerce competitor-analysis prompt framework with no executable code, credentials, persistence, or hidden data access.

Safe to install as a prompt framework. Treat market-share, traffic, conversion, and competitor-performance numbers as estimates unless independently verified, and avoid using it for deceptive or non-compliant competitive tactics.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest description uses very broad trigger phrases like competitor analysis, market analysis, and competitive intelligence, which can cause the skill to activate for generic business research requests beyond its intended scope. Over-broad routing increases the chance that users are funneled into a workflow that produces speculative competitor estimates and aggressive strategic guidance without clear consent or context.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill presents strategic competitor analysis, estimated performance metrics, and recommendations to exploit competitor weaknesses, but the initial description does not warn users that outputs may contain inferred or estimated data and offensive strategic suggestions. This can mislead users into over-trusting speculative intelligence and can normalize ethically risky or potentially harmful competitive actions.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal