Back to skill

Security audit

amazon-listing-audit-pro

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Amazon listing audit tool, but it needs review because API-key handling and review-prompt processing create avoidable security risks.

Review before installing. Use the default ZooData endpoint only, avoid setting ZOODATA_BASE_URL, prefer an environment variable over a persistent config file for the API key, and be aware that review-analysis results can be manipulated by adversarial product reviews. Pin or otherwise verify the installer path before using the README npx command.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
scripts/zoodata.py:910
Finding

Indirect prompt injection through externally sourced review content

Content
View full analysis
str: title = review.get("title") or "" body = review.get("body") or "" full = f"{title}. {body}" if title else body text = full[:500] rating = review.get("rating") or 3 verified = bool(review.get("verifiedPurchase")) return f"""IMPORTANT: Respond ONLY with a JSON object matching the schema below. Output must be in English — translate non-English text before extracting. You are an expert data extraction specialist analyzing product reviews. Extract only what is EXPLICITLY mentioned — do not infer. JSON schema: {{ "sentiment": "positive" | "neutral" | "negative", "mentioned_scenarios": [string], // max 5 noun phrases 1-3 words (Workouts, Gaming) "mentioned_issues": [string], // max 5 Adjective+Noun for PRODUCT DEFECTS (Poor Sound Quality) "mentioned_positives": [string], // max 5 Adjective+Noun for praised aspects (Comfortable Fit) "mentioned_improvements": [string], // max 3 Verb+Noun explicit suggestions (Extend Battery Life) "mentioned_buying_factors": [string], // max 3 noun phrases for purchase reasons (Price Point) "mentioned_pain_points": [string], // max 3 UX frustrations EXPERIENCED AFTER USE (see rule) "user_profiles": [string], // max 3 identities stated EXPLICITLY (see rule) "mentioned_usage_times": [string], // max 3 time/season phrases (Morning, Winter) "mentioned_usage_locations": [string],// max 3 location phrases (Gym, Home) "mentioned_behaviors": [string], // max 5 Verb+Object (Taking Calls, Running) "keywords": [string] // 3-15 salient words from the review }} Rules: - sentiment: positive (4-5 stars or praise), ...[truncated 3174 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/zoodata.py:55
Finding

Bearer API key can be transmitted over plaintext HTTP or to a local listener

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:23
Finding

Installation documentation executes an unpinned package through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims a bounded listing-optimization role while also including credential checks, endpoint probing, review-intelligence pipelines, raw review processing, and broader keyword/brand/product research utilities. Even if some restrictions are described in prose, this kind of description-behavior mismatch weakens informed consent and reviewability, making it easier for a user or orchestrator to invoke higher-risk functionality than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims a bounded listing-optimization role while also including credential checks, endpoint probing, review-intelligence pipelines, raw review processing, and broader keyword/brand/product research utilities. Even if some restrictions are described in prose, this kind of description-behavior mismatch weakens informed consent and reviewability, making it easier for a user or orchestrator to invoke higher-risk functionality than intended.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx skills add SerendipityOneInc/ZooData-Skills without pinning a specific package or repository version. This creates a supply-chain risk: if the referenced package, dependency chain, or resolved remote content changes or is compromised, users may install and execute unexpected code during setup.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises powerful capabilities (env, file_read, network, shell) but does not declare an explicit tool scope such as permissions or allowed-tools at the manifest level. That creates a policy gap where the runtime or hosting agent may expose broader capabilities than users or reviewers expect, increasing the chance of unintended command execution, file access, or secret handling outside the stated listing-audit workflow.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/reference.md (reported line 26)May include surrounding context.

md
# ─── Configuration ───────────────────────────────────────────────────────────

DEFAULT_BASE_URL = "https://api.zoodata.ai/openapi/v2"
API_BASE_PATH = "/openapi/v2"
KEYWORD_DATE_RANGE_MAX_DAYS = 93
KEYWORD_TIMELINE_MAX_DAYS = 61

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/zoodata.py (reported line 50)May include surrounding context.

python
# ─── Configuration ───────────────────────────────────────────────────────────

DEFAULT_BASE_URL = "https://api.zoodata.ai/openapi/v2"
API_BASE_PATH = "/openapi/v2"
KEYWORD_DATE_RANGE_MAX_DAYS = 93
KEYWORD_TIMELINE_MAX_DAYS = 61

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/zoodata.py (reported line 87)May include surrounding context.

python
# ─── Configuration ───────────────────────────────────────────────────────────

DEFAULT_BASE_URL = "https://api.zoodata.ai/openapi/v2"
API_BASE_PATH = "/openapi/v2"
KEYWORD_DATE_RANGE_MAX_DAYS = 93
KEYWORD_TIMELINE_MAX_DAYS = 61

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The review toolkit fetches raw reviews, renders per-review and reduce prompts for another LLM, and aggregates user- or model-produced labels into analysis output. That is a distinct prompt-orchestration capability not mentioned in the manifest, which describes using ZooData endpoints for listing audits and optimization rather than exposing a generic review-tagging pipeline for downstream LLM workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code file contains a natural-language instruction that requires the downstream LLM to output in English and translate non-English input first. That imposes a specific language choice regardless of user preference, which matches the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a listing health check and optimization engine for Amazon sellers, focused on auditing listings, benchmarking, keyword gaps, and improvement recommendations. This file also implements broad standalone capabilities such as market-entry analysis, competitor war-room analysis, pricing analysis, daily market monitoring, opportunity discovery, raw review extraction/prompt generation, and general product/category/brand/price-band research commands, which materially exceed that stated skill purpose.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/zoodata.py (reported line 1234)May include surrounding context.

python
"priceMin", "priceMax", "ratingMin", "ratingMax", "bsrMin", "bsrMax",
                 "salesGrowthRateMin", "salesGrowthRateMax", "sellerCountMin", "sellerCountMax",
                 "variantCountMin", "variantCountMax"):
        val = getattr(args, attr.replace("Min", "_min").replace("Max", "_max")
                      .replace("monthly", "monthly_").replace("review", "review_")
                      .replace("sales", "sales_").replace("Growth", "_growth_")
                      .replace("Rate", "rate_").replace("price", "price_")

Static analysis

No suspicious patterns detected.