Dataify Amazon Seller

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Dataify helper that submits an Amazon seller collection task using a user-provided or saved Dataify API token.

Install this only if you intend to use Dataify for Amazon seller collection tasks. Be aware that a saved DATAIFY_API_TOKEN may be reused for submissions, so keep that token scoped and remove it from your environment if you do not want the agent to use it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly tells the agent to check for and reuse a locally saved DATAIFY_API_TOKEN without requiring clear user consent or even a warning that stored credentials will be accessed. In this context, the skill performs external API calls, so silent credential reuse can cause unauthorized actions on the user's third-party account and reduces user awareness of secret handling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal