Back to skill

Security audit

Amazon Bad Review Analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its Amazon review-analysis purpose, but it can send the saved ARI API key to an environment-selected API server, which needs review before installation.

Install only if you trust ARI and your execution environment. Before using it, ensure ARI_BASE_URL is unset or points only to the legitimate ARI service, protect/revoke the ari_live_ key if it may have run with an untrusted environment, and review paid --confirm actions, exports, and workbench status updates before approving them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ari.py:53
Finding

API Credential Disclosure Through an Unrestricted Base URL Override

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (22)

Tainted flow: 'req' from os.environ.get (line 969, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The request destination is derived from base_url(), which accepts ARI_BASE_URL from the environment, and authenticated requests attach the Bearer API key. If an attacker can influence the environment or wrapper configuration, they can redirect requests to an attacker-controlled host and exfiltrate the API key and request data.

Content

Scanner excerpt · scripts/ari.py (reported line 286)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    try:
        req = urllib.request.Request(url, data=data, headers=headers, method=method)
        with urllib.request.urlopen(req, timeout=TIMEOUT_SEC) as resp:
            note_release(resp.headers)
            raw = resp.read().decode("utf-8")
            out = json.loads(raw) if raw else {"success": True, "data": None}

Tainted flow: 'req' from os.environ.get (line 969, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

This SSE request also uses base_url() from ARI_BASE_URL while sending the Authorization bearer token and analysis payload to the selected host. Because SSE sessions can be long-lived and include sensitive report content, redirecting them to an attacker-controlled endpoint can expose both credentials and business data.

Content

Scanner excerpt · scripts/ari.py (reported line 316)May include surrounding context.

python
try:
        req = urllib.request.Request(
            url, data=json.dumps(payload).encode("utf-8"), headers=headers, method="POST")
        with urllib.request.urlopen(req, timeout=SSE_TIMEOUT_SEC) as resp:
            note_release(resp.headers)
            content_type = resp.headers.get("Content-Type", "")
            if "text/event-stream" not in content_type:

Tainted flow: 'req' from os.environ.get (line 969, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/ari.py (reported line 382)May include surrounding context.

python
base_url() + "/api/v1/public/config",
            headers={"Accept": "application/json",
                     "User-Agent": user_agent()})
        with urllib.request.urlopen(req, timeout=15) as resp:
            note_release(resp.headers)
            body = json.loads(resp.read().decode("utf-8"))
    except Exception:

Tainted flow: 'req' from os.environ.get (line 969, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/ari.py (reported line 479)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    try:
        req = urllib.request.Request(base_url() + path, data=data, headers=headers, method=method)
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            note_release(resp.headers)
            out = json.loads(resp.read().decode("utf-8"))
            if isinstance(out, dict):

Tainted flow: 'req' from os.environ.get (line 969, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The download/export path sends the Bearer API key to the host derived from ARI_BASE_URL and may also write attacker-controlled response bodies to local files. If the environment is maliciously set, this enables credential exfiltration and delivery of untrusted file contents under a trusted-looking workflow.

Content

Scanner excerpt · scripts/ari.py (reported line 970)May include surrounding context.

python
headers = {"Authorization": "Bearer " + require_key(), "User-Agent": user_agent()}
    try:
        req = urllib.request.Request(url, headers=headers, method="GET")
        with urllib.request.urlopen(req, timeout=TIMEOUT_SEC) as resp:
            note_release(resp.headers)
            ctype = resp.headers.get("Content-Type", "")
            body = resp.read()

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states '安装后直接用中文描述需求即可', which directs users to interact in Chinese and does not indicate that other languages are supported or that language choice is optional. This is a natural-language locale/policy concern because it forces a specific language without explicit user opt-in or justification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to use shell commands, access environment-based credentials, perform network calls, and potentially write local configuration, but it does not declare any explicit tool scope or permission boundaries. This creates an over-privileged integration where an agent may invoke powerful capabilities without transparent restriction, increasing the blast radius if the skill is misused, misrouted, or modified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrases are broad enough to match generic requests about complaints, quality issues, or rating drops, which can cause the skill to activate in situations the user did not specifically intend. In this skill, unintended activation is more concerning because it can lead the agent toward networked data collection, local credential setup, or quoted/paid workflows tied to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The display name, short description, and default prompt all require Chinese, but the file does not state that the skill is intended only for Chinese-speaking users or provide any language opt-in. This can violate language/locale policy by implicitly forcing a specific language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document title and all operational instructions are written in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill focused on collecting reviews for a specified ASIN and analyzing 1–3 star negative feedback, root causes, rankings, and trend charts. This CLI also exposes alerts management, category benchmarking, paid category leaderboards, a workbench for review status tracking, single-review AI advice generation, and local export capabilities, which materially extend beyond the stated bad-review analysis scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

A skill advertised as review analysis and reporting is expected to read data and generate insights, but these commands perform state-changing operations on remote resources: POST /api/v1/alerts/read and PUT /api/v1/workbench/reviews//status. Those workflow-management mutations are not justified by the manifest's stated purpose of analyzing negative reviews and producing recommendations/charts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The analysis argument helper sets --language default to zh, causing analysis commands to produce Chinese output unless the user explicitly overrides it. This is a natural-language policy issue because it forces a specific language by default rather than offering a neutral default or explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The voc subcommand hard-codes --language to zh by default, so generated VOC reports are produced in Chinese unless changed by the caller. This enforces a specific language choice without explicit user consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The deepdive subcommand sets --language default to zh, which means its analysis portion will be generated in Chinese by default. This is a locale/language policy violation because a specific language is imposed absent explicit opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage guide materially expands the skill from narrow bad-review analysis into a broad review-intelligence suite, including competitor comparison, purchase-motivation analysis, exports, alerts, benchmarking, and full VOC reporting. This scope mismatch is dangerous because users and host platforms may grant trust, permissions, or purchase consent based on the manifest’s narrower description, while the documentation steers them toward higher-risk or higher-cost actions outside the declared intent.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/ari.py (reported line 1124)May include surrounding context.

python
所以校验不能写死 B 前缀。顺手把值归一成大写,后续命令不必再 upper()。
    """
    for attr in ("asin", "competitor"):
        value = getattr(args, attr, None)
        if value in (None, ""):
            continue
        normalized = str(value).strip().upper()

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The statement says the CLI will not itself download or run remote files for updates, which is narrowly true, but the surrounding update flow describes remote version checks and server-enforced execution gating. This creates an intent-level documentation tension: the text emphasizes safety from remote update execution while the tool still depends on server-side control over what operations may run.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.