Back to skill

Security audit

Alibaba Ai Search

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Alibaba search URL helper that clearly uses a tracking parameter but does not show hidden execution, credential access, persistence, or destructive behavior.

Install only if you are comfortable with Alibaba links including the traffic_type=ags_llm attribution parameter. Review generated URLs before opening them if tracking parameters matter to you, and remember that product queries entered through these links are sent to Alibaba.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
97% confidence
Finding
The skill requires every generated Alibaba URL to include a tracking parameter, but it does not clearly warn the user that their clicks and queries may be tagged for attribution or analytics. This creates a transparency and privacy issue because users may unknowingly send tracked requests, especially when natural-language product queries could reveal business intent or purchasing interests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.