Back to skill

Security audit

亚马逊消费者洞察 · 深度需求报告

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed ARI/Amazon review analysis tool that uses an API key, paid credits, exports, and account-side monitoring features, with clear user-confirmation rules for chargeable or persistent actions.

Install only if you intend to use ARI for Amazon ASIN review analysis and are comfortable giving the skill an ARI API key. Review quotes before confirming paid commands, be careful with schedule, competitor, and watch features because they can create ongoing service-side monitoring or future collection costs, and avoid storing the API key in synced or shared folders.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill explicitly instructs use of shell commands, networked API access, local key storage, and local file export behavior, yet it declares no permissions. This under-disclosure prevents accurate user or platform risk evaluation and can lead to unexpected secret handling, filesystem writes, and external data transmission when the skill is invoked.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The public description frames the skill as a consumer-insight reporting tool, but the instructions authorize substantially broader actions: API-key setup/storage, billing-sensitive paid operations, account checks, watch management, competitor/product management, exports, and workflow execution. This mismatch can cause users or orchestrators to invoke the skill under a much narrower trust assumption than its actual operational scope, enabling unintended account changes, charges, and data handling.

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The skill implements substantial product-operations workflows beyond the manifest's stated consumer-insight reporting scope, including quoted paid operations and execution paths. Scope expansion is dangerous because users and orchestrators may grant trust, credentials, or approval based on the manifest while the code exposes materially different capabilities that can trigger actions and spending.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The code includes workbench, advice generation, alerts, watch, benchmark, leaderboard, and export features that go well beyond the advertised 'consumer insight report' functionality. In an agent setting, this mismatch increases the chance of unintended paid actions, broader data access, or user confusion about what the skill can do.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The invocation text uses broad trigger phrases such as general research, market insight, and consumer study requests, which overlap with many ordinary user intents. In an agent ecosystem, overly broad routing criteria can cause the skill to be selected in contexts where users did not intend external API use, credential-dependent workflows, or billing-related actions.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.