Back to skill

Security audit

生活方式购物基础版

Security checks across malware telemetry and agentic risk

Overview

This skill is a shopping search and product-browsing guide with no installed code, persistence, payment action, or hidden behavior found.

Install only if you want an agent to help browse and search shopping products. Avoid providing private wallet material or payment credentials, and only use callback URLs you control and trust. Treat the documented free version as browsing-only; do not rely on it for checkout, payment, or order handling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description claims broad applicability for 'related development scenarios' without defining concrete activation boundaries, which can cause an agent to invoke the skill outside shopping-specific contexts. In an agent ecosystem, vague scope increases the chance of inappropriate tool use and unintended network actions, especially since the skill advertises executable and read/glob/grep capabilities.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documented `callback_url` allows outbound requests to an arbitrary user-supplied URL, but the skill provides no warning or restriction about data disclosure, SSRF, or calling internal endpoints. In an agent context, this is risky because processing results or metadata could be exfiltrated to attacker-controlled infrastructure or used to probe network-accessible services.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.