Back to skill

Security audit

Amazon 商品页审查

Security checks for vulnerabilities and agentic risk

Overview

This skill is presented as a single Amazon product-page audit tool, but it also documents and ships paid analysis, competitor, monitoring, export, alert, and account-setting workflows that users should review before installing.

Install only if you intend to use ARI as a broader Amazon review and product-operations assistant, not just a narrow page-audit checker. Before using it, review the credit/auto-confirm settings, disable auto-confirm if you want every billable action approved first, and be aware that schedules, watches, competitor bindings, exports, and account alerts may persist or expose ARI account data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:108
Finding
Mandatory Vendor Promotion and Agent Output Hijacking<![CDATA[ ## Vulnerability Details **File Location**: `SKILL.md:108`, `SKILL.md:120-121`, and `SKILL.md:235-237` **Vulnerability Type**: T01: Skill Instruction Hijacking **Risk Level**: Medium ### Evidence The following excerpts are faithful English translations of the relevant Skill instructions: ```markdown 8. After running `check` at the beginning of a session, also run `alerts`. When there are unread negative-review alerts, proactively tell the user and suggest using `workbench` to locate negative reviews and `advise` to generate response recommendations. ``` ```markdown After a VOC report is generated, proactively mention: The language buyers use in reviews is the best source of keywords, and most sellers do not realize this data can be used directly for advertising. ``` ```markdown At the end, briefly list the ASIN/site, sample size, statistical window, reportId, creditsUsed, and current balance. When the output contains a reportUrl, it must be appended at the end using the fixed wording: "View the complete chart-based report online / export: <reportUrl>" ``` ### Technical Analysis The Skill does more than define the workflow necessary to audit an Amazon product page. It instructs the agent to perform unsolicited follow-up actions, introduce advertising-oriented promotional messaging, and append a mandatory vendor-hosted link using fixed wording. These instructions influence the agent's response policy whenever the Skill is loaded. In particular: 1. The agent is instructed to query alerts at the start of a session even when the user only requested a product-page audit. 2. The agent is instructed to promote an additional keyword or advertising use case after generating a VOC report. 3. The final response is required to contain fixed vendor-directed wording whenever a report URL is available. The fixed API origin and report service are part of the declared hosted functionality, so merely returning a requested report URL would not constitute a vul ...[truncated 2138 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Remove mandatory promotional language and fixed vendor-directed closings. 2. Return a report URL only when the user requested a report, export, sharing link, or online visualization. 3. Replace mandatory wording with neutral, optional guidance, such as: “If useful, the hosted report URL is available in the API response.” 4. Do not run `alerts` automatically for unrelated product-page audit requests. Query alerts only when the user requests account alerts or when they have explicitly opted into proactive notifications. 5. Do not introduce advertising or keyword features after every VOC report. Mention them only when relevant to the user's stated objective. 6. Require explicit user consent before performing account-wide queries that are not necessary for the current product audit. 7. Clearly distinguish essential operational instructions from optional product-discovery or marketing guidance. 8. Add a policy stating that user intent and response relevance take precedence over optional vendor engagement recommendations. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (76)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The manifest presents this as a narrow single-product page audit skill, but the body exposes much broader capabilities including paid report generation, competitor comparison, monitoring, exports, account-setting changes, and advertising-related analysis. This mismatch undermines user consent and policy enforcement because callers may authorize a low-risk audit while the skill can perform materially different, potentially billable or state-changing actions.

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest says the skill is not for dual-ASIN comparison, but the documented workflow includes competitor comparison and competitor binding commands. This creates a trust and authorization gap where a supposedly single-product audit tool can analyze additional products and persist related monitoring state.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill description says it is not for advertising, yet it instructs the agent to generate ad keywords, negative keywords, and Search Terms. That is a direct scope expansion into ad-operations behavior and could lead users or upstream policy gates to permit actions they would have declined if disclosed accurately.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill metadata describes a single-product page audit tool, but the code exposes broader capabilities including competitor comparison and multi-workflow product operations. This scope expansion can cause an agent or user to invoke actions outside the approved use case, increasing the chance of unauthorized analysis, unintended billing, and policy bypass through misleading packaging.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
These sections implement product-operations workflows that can quote, run, and track broader operational tasks, far beyond passive page auditing. In an agent context, this materially expands authority and can trigger paid or stateful operations under a skill that users and policy engines may treat as read-only or narrowly scoped.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill documentation and example invocations are entirely in Chinese and instruct the user to send Chinese prompts such as “审查一个 Amazon 商品页…”, with no indication that other languages are supported or that Chinese is required for a justified region-specific reason. This creates a natural-language locale constraint without user opt-in, which matches the policy-violation category.

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill declares no explicit tool scope or permission boundary even though its instructions rely on shell, network, environment access, and local file writes. In an agent environment, missing least-privilege constraints can let the skill invoke more capabilities than users expect, increasing the blast radius of prompt injection, operator error, or misuse.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
1. 运行 `check`,确认账户、邮箱验证状态和可用积点。
2. 用户要 VOC / 评论分析报告时,默认运行 `voc <ASIN> --site <站点>`。
   **返回里有 `autoConfirmed: true` 就说明已经直接生成了**(1.4.5 起:服务端对前几次小额
   付费操作免确认,用户先拿到结果再谈钱),此时把报告讲给用户,并转述 `autoConfirmNote`
   (本次扣了多少、还剩几次免确认、之后会先问)。**不要在拿到结果后再补问「要不要生成」。**
3. 返回 `confirmationRequired: true` 才需要用户确认:报出 `totalCredits` 与余额,
Confidence
95% confidence
Finding
The workflow explicitly allows paid report generation to proceed automatically when the backend marks the request auto-confirmed, with instructions not to ask the user again. Even if the service permits this, it weakens transaction-level user consent in the agent layer and can surprise users with charges for a task they thought was just an audit or quote.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
1. 运行 `check`,确认账户、邮箱验证状态和可用积点。
2. 用户要 VOC / 评论分析报告时,默认运行 `voc <ASIN> --site <站点>`。
   **返回里有 `autoConfirmed: true` 就说明已经直接生成了**(1.4.5 起:服务端对前几次小额
   付费操作免确认,用户先拿到结果再谈钱),此时把报告讲给用户,并转述 `autoConfirmNote`
   (本次扣了多少、还剩几次免确认、之后会先问)。**不要在拿到结果后再补问「要不要生成」。**
3. 返回 `confirmationRequired: true` 才需要用户确认:报出 `totalCredits` 与余额,
   用户同意后运行 `voc <ASIN> --site <站点> --confirm`。该命令会自动补齐采集、等待任务完成、
Confidence
94% confidence
Finding
The skill directs the agent to perform billable operations after minimal confirmation logic controlled largely by service responses. In an autonomous agent context, this reduces user control over spending and can lead to unintended purchases or data-collection actions initiated by ambiguous user requests.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill contains account and billing-management behavior, including modifying auto-confirm spending rules, that is not justified by a simple product page audit purpose. Combining analysis with billing-policy changes raises the risk of unintended charges or user confusion about what the skill is authorized to do.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
用户只说自然语言。网页是补充视图(图表、分享链接、海报),不是把人送走的地方。

**确认与扣点**
- 报价返回 `autoConfirm: true` 时直接生成,不要再问「要不要」。生成后一句话交代:本次扣了多少、
  还剩几次免确认(或「免费版小额不问」)。策略由服务端决定:免费版小额不问;付费版前几次不问,之后先问。
- 用户说「以后别问了 / 50 以内直接做」→ 运行 `autoconfirm 50`;说「以后每次先问我」→ `autoconfirm off`;
  说「恢复默认」→ `autoconfirm default`。这是唯一需要你代用户设置的东西,设完复述一句当前规则。
Confidence
95% confidence
Finding
The instruction to generate immediately when autoConfirm is true tells the agent to rely on service-side charging policy instead of fresh user consent. This is dangerous because the skill already has broader-than-declared capabilities, so autonomous paid execution increases the chance of unauthorized or unexpected charges.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
**确认与扣点**
- 报价返回 `autoConfirm: true` 时直接生成,不要再问「要不要」。生成后一句话交代:本次扣了多少、
  还剩几次免确认(或「免费版小额不问」)。策略由服务端决定:免费版小额不问;付费版前几次不问,之后先问。
- 用户说「以后别问了 / 50 以内直接做」→ 运行 `autoconfirm 50`;说「以后每次先问我」→ `autoconfirm off`;
  说「恢复默认」→ `autoconfirm default`。这是唯一需要你代用户设置的东西,设完复述一句当前规则。
- 报价需要确认时,只说两个数:这次多少积点、余额多少,然后等用户一个「好」。采集是**固定单价**:直接说「15 积点/页 × 3 页 = 45 积点」,不要说成「预计 / 最多」——价格不会浮动;商品评论不够这么多页时只收实际采到的页数,差额自动退回(`pricingNote` 已写好这句)。不要罗列参数。
Confidence
93% confidence
Finding
The skill instructs the agent to change auto-confirm thresholds on the user's behalf, which is an account-level spending policy change. That can affect future transactions outside the current task and materially increase the risk of silent or repeated charges.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
Although the manifest says the skill is not for automatic page modification, the documented behavior includes changing account-level auto-confirm settings and enabling product schedules. These are state-changing administrative actions that can affect future billing and execution behavior beyond the current audit.

Static analysis

No suspicious patterns detected.