Back to skill

Security audit

Amazon 商品转视频脚本

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese-language Amazon product analysis workflow that uses browser access to public product and review content to produce marketing scripts.

Install this if you want an agent to browse a supplied Amazon product page and use public listing/review text to draft Chinese social-video scripts. Be aware it defaults to Chinese output and may create local markdown deliverables if used as written.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions are broad enough to activate on generic requests about video scripts or product suitability whenever an Amazon link is present, even if the user did not intend to invoke this skill. That can cause inappropriate routing, unnecessary browsing of third-party pages, and collection of external content when a narrower tool or a normal chat response would have been more appropriate.

Natural-Language Policy Violations

Medium
Confidence
77% confidence
Finding
The skill is defined as Chinese-focused and does not ask for the user's preferred language before beginning analysis. This can cause unintended disclosure or transformation of user-provided content into a different language/context, and may reduce user control or accuracy for multilingual or region-specific workflows.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill metadata and triggers explicitly constrain the output to Chinese without indicating user choice or locale negotiation. This can override user expectations, reduce usability for non-Chinese users, and in some agent settings may cause unintended behavior or policy bypass if language selection is assumed to follow user preference.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.