Logistics Tracking

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly described package-tracking integration, but users should treat the external npm MCP server, 17track data sharing, and optional API key carefully.

Before installing, verify the @shopmeagent/logistics-tracking-mcp package source and consider pinning a version. Use the official 17track API-key mode when possible, protect TRACK17_API_KEY, and secure any hosted MCP endpoint with HTTPS, authentication, and rate limits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill sends user-provided tracking numbers to 17track either through the official API or by automating the 17track website with Playwright, but the user-facing description does not clearly disclose this third-party data transfer. Tracking numbers can reveal purchase activity, shipment relationships, approximate location, and other sensitive logistics metadata, so undisclosed sharing creates a privacy and compliance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal