Back to skill

Security audit

Amazon Keyword Traffic Analysis

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Amazon keyword and ASIN traffic analysis integration that uses scoped ZooData API calls and does not show hidden mutation, persistence, or exfiltration behavior.

Install only if you are comfortable using a ZooData API key for Amazon keyword and ASIN research. Expect API calls to consume credits and send the requested keywords, ASINs, dates, marketplaces, and any public page URLs to ZooData; provide SQP or Ads exports only when you want seller-funnel or advertising analysis.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
72% confidence
Finding
The skill description promises narrowly scoped Amazon keyword-traffic analysis, but the embedded instructions indicate access to broader product, brand, pricing, review, and market-research workflows. This scope expansion increases the chance that an agent will invoke data acquisition paths or analyses the user did not intend, weakening least-privilege expectations and making oversight harder.

Static analysis

No suspicious patterns detected.