Back to skill

Security audit

亚马逊变体分析 · 颜色尺寸口碑对比

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it exposes a much broader ARI account, monitoring, export, and paid-operations client than its variant-analysis name suggests.

Review this as a broad ARI Amazon review and product-operations assistant, not just a variant-comparison skill. Install only if you are comfortable giving it an ARI API key, letting it read account product/review/report data, creating or changing monitoring/competitor/workbench state when asked, and exporting business data to local files. Treat all --confirm actions and monitoring setup as explicit spending or account-management decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
The skill is presented as a narrowly scoped Amazon variant-analysis tool, but the documentation authorizes a much broader operational surface: account setup, billing-sensitive actions, exports, monitoring, competitor workflows, and multiple paid analysis modes. That scope mismatch is dangerous because it can mislead users and orchestrators into granting trust or invoking actions they did not expect, increasing the chance of unintended data access, paid operations, or broader account modifications.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The file implements a broad multi-purpose ARI client, including monitoring, competitor management, operations tooling, workbench, alerts, exports, and paid analysis workflows that substantially exceed the declared 'amazon-variant-analysis' scope. In an agent-skill setting, this scope mismatch is dangerous because it grants the skill many more data-access and state-changing capabilities than users or policy reviewers would reasonably expect from the manifest.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
These sections expose state-changing controls for watches, monitoring schedules, competitor relationships, and review/workflow management despite the skill being presented as a variant-comparison tool. Such hidden or unjustified mutating actions increase the risk of unauthorized account changes, unintended billing-triggering automations, and user deception about what the skill can do.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The generic product-operations workflow can run arbitrary server-supported workflow/focus combinations, which is much broader than comparing child ASIN variants under a parent. In a constrained skill ecosystem, this effectively turns a narrowly described skill into a general operations agent, undermining least privilege and creating opportunities for unreviewed paid or stateful actions.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
Local export of reviews and reports to arbitrary output paths is broader than the manifest's stated analytical purpose and creates an exfiltration/retention channel for potentially sensitive business data on the local filesystem. In an agent context, file-writing capability is especially sensitive because it can persist harvested data outside the expected interactive workflow.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The usage guide materially expands the skill from a narrow variant-analysis tool into a broad Amazon review/operations assistant, including collection, exports, monitoring, alerts, competitor comparison, and paid operational workflows. This creates a scope mismatch that can mislead the agent or user into invoking capabilities not declared in the manifest, weakening least-privilege expectations and increasing the chance of unauthorized or surprising actions involving paid APIs and account-bound data.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
Branding the skill as a general 'ARI Amazon 评论智能助手' contradicts the manifest's specialized variant-analysis purpose and signals that the skill may be used as a catch-all interface to wider functionality. In an agent setting, this ambiguity is dangerous because it encourages broader task routing and trust than the declared skill scope warrants, which can lead to misuse of credentials, overbroad data handling, or unintended billable operations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.