Dataify Amazon Product List

Security checks across malware telemetry and agentic risk

Overview

This skill transparently submits user-requested Amazon product-list collection jobs to Dataify using a Dataify API token, with no evidence of hidden or destructive behavior.

Install only if you want the agent to create Dataify Amazon collection tasks. Treat DATAIFY_API_TOKEN as a secret, prefer session-scoped or protected storage where possible, and review the displayed keyword, domain, page count, and file name before allowing submission.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill tells the agent to automatically reuse a saved DATAIFY_API_TOKEN from the local environment if present, without an explicit warning, consent step, or guidance on safe credential handling. In this context, that increases the risk of silent credential use, unintended external API calls, and accidental exposure or misuse of a long-lived token.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal