Back to skill

Security audit

Amazon Product Search by Gecho

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for Amazon product research, but it relies on a logged-in browser session and may save collected listing data locally.

Install only if you are comfortable giving Gecho Bridge and its Chrome extension access to run Amazon searches from your logged-in browser session. Use a directory you control for `save_dir`, review saved result files before sharing them, and remember that results may include session-influenced details such as region, availability, or pricing.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Low
Confidence
89% confidence
Finding
This markdown file states that the skill collects structured Amazon data and saves raw results when possible, but it does not give a direct user warning about local persistence, overwrite risk, or that saved files may contain account-session-derived browsing data. Because SQP-2 applies to markdown files when behaviors affecting user data or privacy are not clearly warned about, this is a missing disclosure.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
Join the [WeCom group](https://github.com/gecho-ai/gecho-bridge/blob/main/qywx.jpg) or use the [1:1 support QR code](https://github.com/gecho-ai/gecho-bridge/blob/main/wx.jpg).

## Output guidelines

For success:
- Say the tool completed.
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Static analysis

No suspicious patterns detected.