AI店长 - 电商助手

Security checks across malware telemetry and agentic risk

Overview

This e-commerce assistant uses public web search and optional monitoring as advertised, with no evidence of hidden credential access, data theft, or destructive behavior.

Install this if you want an e-commerce research and copywriting helper. Before using monitoring, specify the exact products, platforms, schedule, and when it should stop. Avoid entering confidential launch plans as search terms, and review generated prices, inventory claims, scarcity language, and compliance-sensitive copy before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill uses very broad, natural-language activation examples such as asking the assistant to analyze markets, monitor competitors, or generate content, without clear boundaries separating ordinary conversation from explicit skill invocation. This can cause accidental triggering, over-collection of web data, or unexpected scheduled monitoring actions when a user did not intend to invoke the skill's full workflow.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal