Back to skill

Security audit

amazon-analysis

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate Amazon research skill that uses ZooData API access for product and market analysis, with credit and data-sharing considerations users should understand.

Install only if you are comfortable sending Amazon research inputs such as keywords, categories, ASINs, dates, and filters to ZooData and spending ZooData API credits. Avoid using it for confidential product ideas unless that third-party data sharing is acceptable, and prefer explicit Amazon/FBA/product-research prompts so broad workflows do not run unnecessarily.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill clearly instructs the agent to use environment credentials, read local files, and make network calls, but the finding indicates those capabilities are not formally declared as permissions. That creates a policy and review gap: a host system may grant broader access than users expect, or fail to enforce least-privilege controls around sensitive resources such as ZOODATA_API_KEY and local config files.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file expands the skill from general Amazon research into direct listing copy creation and optimization, which is a material scope change from the manifest description. That mismatch can cause the agent to perform unintended persuasive or marketing actions under a broader skill invocation, increasing the chance of unsafe or unauthorized behavior.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example prompt "Analyze the yoga mat market on Amazon" is broad enough to match many ordinary user requests, which can cause this skill to be invoked when a user did not specifically intend third-party Amazon research. In this skill's context, over-broad triggering is more concerning because invocation may lead to multi-endpoint external API calls and transmission of user query content to ZooData.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README describes API key setup and extensive third-party API usage but does not clearly warn that user queries, keywords, ASINs, and related research inputs may be sent to ZooData. In this skill's context, that omission is material because the skill is explicitly designed for broad, multi-endpoint research workflows, increasing the likelihood of transmitting sensitive business interests or proprietary product ideas without informed user awareness.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases for the composite recommendation workflow are generic enough to match ordinary shopping or advice-seeking requests, which can cause the agent to invoke this skill outside a clearly bounded Amazon-analysis context. Over-broad activation increases the chance of unintended tool use, unnecessary external API access, and contextually incorrect responses, especially when the workflow proactively gathers user profile data and chains multiple commands.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The seller-origin case-study trigger includes a broad phrase like 'sellers from a specific country', which could activate on general discussions about geography, sourcing, or marketplace behavior without sufficient Amazon-specific scope. Because this workflow analyzes seller origin and can touch on nationality-related attributes, accidental activation creates elevated risk of misclassification, sensitive inference, or generation of biased analysis in response to loosely related requests.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Phrases such as 'full picture' and 'cross-validate' are highly ambiguous and are likely to overlap with many normal user requests unrelated to this Amazon research workflow. In this skill, activation leads to a broad multi-endpoint sequence, so ambiguous routing can trigger excessive data retrieval, unnecessary external calls, and misleading outputs when the user did not intend a full Amazon market analysis.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The competitor-analysis trigger phrases are broad enough to match ordinary user requests about products or selling points without clearly requiring listing-analysis intent. This can cause the skill to activate in contexts where users wanted neutral research, leading to unintended data pulls and content-generation-adjacent behavior.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Phrases like 'write listing,' 'generate bullet points,' and 'write title' are highly generic and likely to overlap with many common assistant requests outside this skill's intended routing boundaries. If auto-triggered, the skill could steer the agent into marketing-content generation and external-data workflows the user did not specifically request.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Diagnosis triggers such as 'optimize my listing' or 'what's wrong with my listing' are ambiguous and can match broad content-improvement requests. In this skill, ambiguous routing is more dangerous because activation leads to multi-endpoint competitive analysis and prescriptive commercial recommendations, not just passive summarization.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.