Back to skill

Security audit

Xianyu Auto Shop

Security checks across malware telemetry and agentic risk

Overview

This skill is not malware in the inspected files, but it asks for powerful automation permissions to run unattended marketplace actions with too little user control described.

Review carefully before installing. Only use this if you are comfortable granting device automation and notification access for a marketplace seller account, and keep message replies and listing/title changes supervised because the skill does not document strong limits, review steps, or an easy stop mechanism.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill advertises broad automation capabilities such as automatic listing polishing, title optimization, and auto-reply behavior without clearly defining scope, limits, or user-controlled boundaries. In a marketplace context, vague automation claims can conceal persistent background actions that modify listings or messages in ways that violate platform rules, cause account sanctions, or act beyond the user's intended consent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The markdown describes always-on automated messaging and scheduled listing modifications but omits a clear warning that the skill can continuously send replies and alter marketplace content without per-action review. In the context of an e-commerce platform, this is more dangerous because unattended messaging and SEO/title changes can mislead buyers, trigger anti-abuse systems, and create compliance, reputation, or account-lockout risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.