Back to skill

Security audit

amazon-review-intelligence-extractor

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed ZooData-powered Amazon review analysis skill that uses an API key and paid API calls, with sensitive behavior mostly scoped to its stated purpose.

Install this if you want Amazon review and market-context analysis through ZooData. Use only the documented review-related commands, provide a ZooData API key only if you are comfortable sending ASINs, keywords, category paths, marketplace/date values, and numeric filters to ZooData, and ask for a credit estimate before broad scans.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill declares no explicit permissions while the content clearly describes access to environment secrets, local file reads, and outbound network use. That mismatch can bypass user or platform expectations about what the skill is allowed to do, increasing the chance of unintended secret exposure or unreviewed external data transfer.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The skill is presented as a narrowly scoped review-insights tool, but the documented behavior reaches far beyond that into broad market intelligence, competitor analysis, keyword workflows, listing audit, pricing analysis, historical trends, and local prompt/aggregation utilities. This scope expansion materially increases attack surface and the risk of unauthorized data access, unexpected external calls, and execution of functions a user did not intend to authorize.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill is presented as an Amazon review-intelligence extractor, but the code exposes a much broader capability set including market-entry, pricing, competitor, keyword, and listing-audit workflows. That scope expansion materially increases the data exfiltration surface and can cause an agent or user to invoke powerful external-research operations they did not knowingly authorize under the declared purpose.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The keyword intelligence endpoints collect search-market telemetry unrelated to the stated review-insights function. In an agent setting, this hidden capability broadens outbound data processing and can be abused to perform competitor/search intelligence under the cover of a narrower review-analysis skill.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The pricing-analysis and market-entry composites orchestrate many external calls and derive strategic market intelligence far beyond review extraction. In context, that mismatch increases risk because agents may autonomously trigger extensive third-party analysis and credit consumption without user awareness consistent with the published skill description.

Vague Triggers

Medium
Confidence
76% confidence
Finding
The trigger phrases are broad and overlap with generic analytics and feedback requests, which can cause the skill to activate in contexts where the user did not specifically intend external API-backed Amazon review analysis. Ambiguous activation raises the likelihood of unnecessary credential use, unintended network calls, and surprise credit consumption.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.