Amazon Serp Analysis

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Amazon market-analysis workflow that may call scraping and analytics tools, with no hidden persistence or destructive behavior found.

Installers should understand that running this skill can make external scraping and MCP-backed analytics requests using configured service credentials. Invoke it with an explicit Amazon seed keyword and review availability/scope of optional SellerSprite and ClickHouse tools before relying on the output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill’s trigger list is very broad and includes generic market-analysis phrases in both Chinese and English, which increases the chance of unintended activation in unrelated conversations. Unintended invocation can cause the agent to launch scraping and analysis workflows without clear user intent, leading to unnecessary external requests and possible data handling that the user did not expect.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal