Back to skill

Security audit

amazon-pricing-command-center

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed ZooData pricing-analysis helper, but it bundles a broader research CLI that users should keep scoped to pricing tasks to avoid unexpected API credit use.

Install this if you want ZooData-backed Amazon pricing analysis and are comfortable providing a ZooData API key. Keep runs limited to the documented pricing workflow, confirm estimated credit usage before batch or broad analyses, and avoid asking the agent to use unrelated research, review, or keyword subcommands unless you intentionally want those broader ZooData queries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The skill is presented as a narrowly scoped pricing tool, but the bundled shared CLI is described as exposing all ZooData endpoints, including unrelated research, review, monitoring, audit, and discovery functions. That scope expansion undermines least privilege and user informed consent: an invoking agent or downstream workflow could access broader data or perform broader operations than the user reasonably expects from a pricing-only skill.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill implements broad market-entry, competitor, review, listing-audit, radar, and opportunity-scan workflows that materially exceed the pricing-focused manifest. This scope mismatch can expose users to unexpected data collection, larger-than-expected external API usage, and hidden operational behavior, which is particularly risky in agent skills where manifest descriptions are relied on for least-privilege trust decisions.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
Undisclosed keyword-intelligence endpoints expand the skill beyond advertised pricing analysis into broader search/traffic intelligence. In an agent context, hidden capabilities are dangerous because they bypass user and platform expectations about what data the skill may query and transmit to third-party services.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.