Back to skill

Security audit

立创商城自动化技能

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it gives an agent broad browser control over shopping, order, account, and file-upload workflows without clear approval checkpoints.

Review before installing. Use this only for clearly requested LCSC tasks, and require the agent to summarize and get explicit approval before changing a cart, uploading BOM or PCB files, submitting an order, exporting cookies, or using an authenticated account session.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill’s trigger scope is very broad, including '任何涉及立创商城的页面操作' and language that it 'must' use browser automation for essentially any LCSC-related task. That can cause the agent to invoke a high-privilege web automation skill for low-risk informational requests, increasing the chance of unintended navigation, account-context actions, or escalation into purchasing workflows without necessity.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly supports adding items to cart, BOM matching, PCB/SMT ordering, and file upload flows, but provides no guardrails such as confirmation prompts, cost review, destination review, or warnings before irreversible/account-affecting actions. In an authenticated browser session, this can lead to accidental purchases, disclosure of uploaded design files/BOMs, or unintended order submission.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
Documenting cookie import/export as a standard capability without privacy or account-safety restrictions exposes session-handling functionality that can enable account takeover, session leakage, or cross-account confusion if misused. In the context of an e-commerce and order-management skill, cookies may grant access to identity, order history, saved carts, addresses, and purchasing capability.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.