Back to skill

Security audit

Sellersprite Skills

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed SellerSprite Amazon research skill pack, with risks mainly around accidental API usage and locale assumptions rather than hidden or destructive behavior.

Install if you intend to use SellerSprite for Amazon marketplace research. Confirm the target marketplace and language before running workflows, watch for API quota usage from parallel calls, and avoid publishing reviewer names or other personal review details unless necessary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The README states that comprehensive skills can be triggered by `/命令` or by referencing the skill name in other clients, but it does not define strong activation boundaries, confirmation steps, or disambiguation rules. In an agent environment, broad natural-language triggers can cause accidental invocation of data-gathering workflows when a user merely discusses a capability, leading to unintended tool use, excess data access, or surprising side effects.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The tactical skills section repeats that skills are triggered by citing their names in conversation, which is a vague invocation rule for many narrowly scoped actions. Because the file lists numerous similar skill names, an agent may misfire on ambiguous user text or chained planning discussions, causing unintended execution of market-analysis or product-research actions without sufficiently explicit user consent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The tactical skills are described as being triggered by mentioning broad natural-language names in conversation, which can overlap with ordinary user requests and cause unintended skill activation. In an agent environment, this can lead to the wrong workflow running, unnecessary tool calls, and analysis based on assumptions the user did not explicitly authorize.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The skill is entirely written in Chinese and prescribes Chinese-language interaction/output without offering any language selection or fallback. This can cause user confusion, misinterpretation of analysis results, and unsafe decision-making if a user cannot fully understand the workflow or recommendations, though it does not directly enable code execution or data exfiltration.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill is entirely written in Chinese and instructs output in Markdown tables without offering any language-selection mechanism. This can cause unsafe or incorrect use by users or downstream agents that expect another language, leading to misunderstanding of pricing recommendations or degraded interoperability, though it is not a classic security exploit.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill is entirely written to operate in Chinese and does not disclose a locale restriction or offer a language fallback. This can cause users to misunderstand parameters, defaults, and report outputs, which is especially risky in a workflow that drives business decisions from structured filtering criteria and tool results.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill hard-codes `marketplace: "US"` in its example workflow without asking for the user's target marketplace or explaining why US is required. In an e-commerce research skill, this can mislead users into running analysis against the wrong region, producing inaccurate market conclusions and poor inventory or advertising decisions, though it does not create direct code-execution or data-exfiltration risk.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The second step repeats the same fixed `US` marketplace, reinforcing a locale assumption across the full comparison workflow. Because this skill is specifically for seasonal demand forecasting, using the wrong marketplace can distort keyword seasonality patterns and cause users to pre-position inventory for the wrong market, increasing operational and financial risk.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.