Etsy Pricing Strategy

Security checks across malware telemetry and agentic risk

Overview

This is a simple Etsy pricing advice skill with no credential requests, direct Etsy access, or hidden automation, though one example prompt is somewhat broad.

Reasonable to install if you want Etsy pricing guidance. Before running the npx install command, confirm you trust the referenced Nexscope source, and avoid giving the assistant Etsy credentials, session cookies, or API tokens because this skill is for strategy advice, not direct shop automation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are broad, generic requests like asking for best practices, audits, or implementation plans, which overlap with normal assistant usage and can cause the skill to activate unintentionally. This increases the chance that users are routed into domain-specific guidance or promotional content when they did not explicitly request this skill, creating prompt-scope confusion and potential misalignment.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal