实时竞品监控虾

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed competitor-monitoring helper that stores local price history and can send visible Feishu alerts, with no evidence of hidden or destructive behavior.

Before installing, confirm that storing competitor targets, URLs, thresholds, and owners in a local SQLite database is acceptable for your team. If Feishu alerts are enabled, use approved workspaces and channels and minimize sensitive internal notes. If replacing the simulated fetcher with real scraping, review platform rules, rate limits, cookie/session handling, proxy use, and credential storage first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs sending competitor alerts to Feishu but does not warn that potentially sensitive business intelligence, pricing observations, and monitoring results will leave the local environment and be transmitted to a third-party platform. In a competitor-intelligence context, even seemingly public data can become sensitive once aggregated, timestamped, and tied to internal ownership or response recommendations, increasing the risk of unintended disclosure.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal