Back to skill

Security audit

Ecommerce Review Analyzer

Security checks across malware telemetry and agentic risk

Overview

This skill openly automates ecommerce review collection and report generation, with privacy-sensitive outputs users should handle carefully.

Install only if you are comfortable letting the agent use a logged-in browser session for Taobao, JD, or Pinduoduo review pages. Confirm the exact product or store before running it, and treat generated DOCX/PDF reports as files that may contain customer review text and account-visible details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation example includes a generic phrase, "帮我分析这个产品的用户反馈", which could match ordinary conversation and trigger this high-privilege skill unintentionally. Because the skill uses browser automation against logged-in ecommerce sessions and extracts review/user data, accidental activation increases the chance of unintended data access and collection.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill states that it inherits the user's logged-in browser session, but it does not clearly warn that automation will access account-scoped ecommerce data and include review content, usernames, dates, and store details in generated reports. This creates a privacy and consent risk because users may not realize the tool is operating with their authenticated session and exporting collected data into documents.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal