Cn Amazon Listing Auditor

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Amazon listing audit skill with no executable code, credentials, persistence, or hidden data access.

Install this if you want Amazon listing feedback framed for Chinese or ESL sellers targeting Western buyers. Be aware that the broad triggers may invoke it for generic listing-review requests, and consider specifying the target marketplace and audience when using it. Treat the external rewrite-service links as optional marketing, not required functionality.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad phrases such as 'listing review' and 'listing quality' that can match many generic ecommerce requests outside the skill's intended scope. This can cause the agent to invoke the skill unexpectedly, leading to inappropriate routing, irrelevant output, or accidental exposure of user content to a skill they did not intend to use.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill is explicitly framed around adapting listings to 'Western buyers' and 'Western-language/cultural' expectations without asking the user which market, locale, or style they want. That can push culturally normative rewrites by default, producing biased or misaligned recommendations and potentially harming users targeting other English-speaking audiences or different brand positioning.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal