Back to skill

Security audit

Yunlv Pod Agent

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed POD business-advice skill with an external strategy API, but it does not show hidden execution, store control, credential harvesting, or destructive behavior.

Install only if you trust YunlvAI with the POD strategy details you provide and can store TRADEGPT_API_KEY securely. Keep any connected commerce or customer-service tools least-privilege, require human approval for refunds, address changes, bulk listings, and promotions, and avoid sending customer data or store credentials unless you have separately reviewed that vendor.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
Several trigger terms, especially broad commerce phrases like '上架建议' and generic POD/AI wording, may cause the skill to activate in ordinary e-commerce conversations outside the user's actual intent. Over-broad activation can route users into unnecessary external-API-backed advice flows, increasing prompt-scope confusion, accidental data disclosure, and misuse of a domain-specific skill in unrelated contexts.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The description repeatedly uses broad activation language such as 'Use when user needs...' across a wide set of POD and AI-business scenarios, but it does not define boundaries or exclusion criteria. This can cause the skill to be invoked in loosely related commercial conversations, increasing the chance of unnecessary external API use, irrelevant automation, or unintended handling of sensitive business data.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Several trigger phrases are broad within normal e-commerce contexts, including terms like '上架建议' and 'print on demand', which may appear in benign discussions not actually requiring this specific skill. Overbroad triggers increase unintended invocation risk, potentially exposing user prompts or business context to the configured third-party API when a more appropriate local or narrower skill should have been used.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The article explicitly promotes L4 customer-service agents that can autonomously perform sensitive account actions such as refunds, order lookup, and address changes, but it does not warn about the need for user authorization, audit logging, fraud controls, or protection of customer data. In a POD operations skill, this normalizes handing transactional and personal-data actions to automation, which can lead to unauthorized refunds, account abuse, privacy violations, and financial loss if implemented unsafely.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.