Back to skill

Security audit

Amazon 全链路调研:搜索、商品详情与评论分析【Gecho 官方】

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Amazon research helper that routes user-requested product and review lookups through Gecho, with no evidence of hidden or destructive behavior.

Before installing, confirm you are comfortable using Gecho Bridge and its Chrome extension with a logged-in Amazon session. Use save_dir only for directories you approve, because product and review research results may be stored locally as JSON.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
93% confidence
Finding
The skill explicitly supports saving Amazon product and review results to local JSON files, but the user-facing description does not clearly warn that collected marketplace data may be written to disk. This can create an informed-consent and data-handling issue: users may trigger local persistence of scraped research outputs without realizing artifacts are being stored, which is more sensitive here because review text and product research may persist beyond the session.

Static analysis

No suspicious patterns detected.