Back to skill

Security audit

Amazon 商品搜索【Gecho 官方】

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Amazon product-search workflow that uses Gecho’s MCP and a logged-in browser session, with no evidence of hidden or destructive behavior.

Install this only if you are comfortable connecting Gecho to a Chrome session where you are logged into Amazon. Review the Gecho Bridge and Chrome extension before use, choose an appropriate save directory, and avoid using it for generic research requests unless you specifically want Amazon marketplace data.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger condition is broad enough to match generic 'research', 'structured results', or 'save data' requests, which can cause the agent to invoke this Amazon-specific skill when the user did not explicitly intend Amazon or Gecho tooling. In context, this increases the chance of inappropriate tool routing, unnecessary use of authenticated browser sessions, and collection of marketplace data under the wrong task scope.

Static analysis

No suspicious patterns detected.