Amazon Paapi

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Amazon Product Advertising API helper, but users should handle the required Amazon API credentials more carefully than the setup text suggests.

Before installing, treat the Amazon access key and secret key as sensitive. Prefer a credential manager or protected environment configuration, restrict any local `.env` file permissions, and avoid committing or syncing it. Also expect this version to provide only the declared `ama-api` lookup command, despite documentation mentioning additional tracker commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The setup instructs users to append Amazon access and secret keys into a plain-text ~/.env file without any warning about file permissions, secret managers, or shell-history exposure. This increases the chance that long-lived API credentials are disclosed through local compromise, backups, dotfile syncing, or accidental sharing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal