Back to skill

Security audit

listing-optimizer-lite

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only e-commerce listing helper with no executable code, account access, persistence, or hidden data flow.

Safe to install for drafting listing copy. Do not provide passwords, API keys, customer personal data, seller-account credentials, or confidential product formulas unless you have separately verified the privacy and retention policy of the AI platform running the skill. Review generated marketplace copy before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The FAQ states that input data is not persistently stored and will not be used for model training, but a markdown skill file cannot enforce or verify those guarantees across whatever underlying LLM platform or agent runtime executes it. This can mislead users into sharing sensitive data under false privacy assumptions, increasing the risk of unintended disclosure or policy noncompliance.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill metadata sets `language: zh-CN`, and the content is written to operate primarily in Chinese without any explicit user opt-in or negotiation of preferred language. This can override user expectations and cause responses in an unintended locale, which may lead to misunderstanding of generated commerce content, policy guidance, or marketplace formatting instructions.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.