Back to skill

Security audit

Etsy Product Data API - Listings, Shops, Reviews

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Etsy data lookup helper that uses Scavio's API and does not install code or request unusual local access.

Install only if you are comfortable using Scavio as a third-party service for Etsy lookups. Treat the Scavio API key as a secret, monitor credit usage, and avoid putting private or identifying information into search terms unless needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
95% confidence
Finding
The skill sends user-supplied queries, listing IDs, and shop identifiers to a third-party API service but does not clearly warn users about that data transfer. While the transmitted data is not highly sensitive by default, the omission creates a privacy and transparency issue because users may not realize their inputs are being shared outside the host system.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:37