Back to skill

Security audit

Amazon Keyword Research

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a disclosed Amazon product research helper that sends product keywords to public Amazon and web research endpoints, with no evidence of credential access, persistence, or destructive behavior.

Install this if you want an agent to run Amazon keyword research using public Amazon autocomplete, web search, and trend data. Treat product keywords as data that may be sent to external services, review the bundled script before use, and invoke it for explicit Amazon market research tasks rather than general shopping conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill instructs the agent to execute a local shell script and use network-capable tools, but the manifest shown does not declare those permissions. Undeclared shell/network capability weakens user and platform visibility into what the skill can do, increasing the risk of unexpected command execution or outbound requests when the skill is invoked.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger description is extremely broad and says to use this skill for almost anything related to Amazon product research, including vague questions like whether a product is good to sell. Over-broad auto-triggering can cause the agent to invoke shell and network actions in contexts where the user did not clearly request this skill, leading to unnecessary data access, unexpected external queries, and reduced user control.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.