Ecommerce Email Marketing Builder

Security checks across malware telemetry and agentic risk

Overview

This appears to be a cart-recovery marketing guidance skill, with one compliance-sensitive opt-in recommendation users should review before applying.

Before using the recommendations in a real storefront, treat any email/SMS/push opt-in advice as a draft and confirm it against applicable privacy, telecom, platform, and email-service rules. Prefer clear affirmative consent, keep consent records, and separate transactional messages from promotional marketing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly recommends a pre-checked checkout email opt-in without any compliance caveat. In many jurisdictions and platforms, pre-checked consent for marketing emails is non-compliant or invalid, which can expose users to privacy violations, regulatory penalties, complaints, and ESP/platform enforcement; the e-commerce context makes this more dangerous because the guidance is operational and likely to be copied directly into real storefronts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal