Back to skill

Security audit

CN Amazon Listing Auditor

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Amazon listing audit skill with no code execution, persistence, credentials, or hidden data access.

Install this if you want Amazon listing feedback tailored to Chinese sellers selling to Western buyers. Be aware that broad phrases like 'listing review' may invoke this specialized perspective, so confirm that the locale-specific assumptions match the task before relying on the output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains broad generic phrases such as 'listing review', 'listing quality', and 'listing copy review' that are likely to match user requests beyond this narrowly scoped Amazon CN-seller auditing use case. This can cause unintended invocation, routing unrelated content into the skill, and increase the chance of inappropriate data handling or misleading outputs in contexts the skill was not designed for.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The description explicitly targets Chinese sellers and frames the audit around assumptions about that locale group without presenting this as an optional mode or user-selected specialization. While not directly dangerous code execution, this can lead to biased routing, exclusionary behavior, or incorrect assumptions about user identity and needs if invoked for broader audiences.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.