Back to skill

Security audit

Amazon Product Api Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Amazon data extraction purpose is coherent, but it unsafely tells users they may provide a BrowserAct API key in chat.

Review before installing. Configure BROWSERACT_API_KEY only through your local environment or an approved secret manager, do not paste the key into chat, and rotate it if it has already been shared. Expect product search inputs and the BrowserAct bearer token to be sent to BrowserAct’s API when the skill runs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:28
Finding

Skill instructions encourage disclosure of an API key through chat

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:28-31
Vulnerability Type: Credential exposure through an insecure communication channel
Risk Level: Medium

Vulnerable Code

markdown
Before running, check the `BROWSERACT_API_KEY` environment variable. If not set, do not take other measures; ask and wait for the user to provide it.
**Agent must inform the user**:
> "Since you haven't configured the BrowserAct API Key, please visit the [BrowserAct Console](https://www.browseract.com/reception/integrations) to get your Key."

Technical Analysis

The documentation instructs the agent to ask the user to provide the BROWSERACT_API_KEY when it is not configured. API keys are authentication credentials and should not be entered into conversational interfaces. Chat content may be retained in conversation history, application logs, telemetry, or agent context and may be visible to parties that would not otherwise have access to the user's local secret store.

The script legitimately needs this credential to authenticate with the declared BrowserAct HTTPS API. However, obtaining the key through chat is unnecessary because the implementation already supports reading it from the BROWSERACT_API_KEY environment variable. The network transmission to https://api.browseract.com is consistent with the Skill's documented functionality; the identified weakness is the credential acquisition guidance rather than the declared API request itself.

Attack Path

  1. A user invokes the Skill without configuring BROWSERACT_API_KEY.
  2. The agent follows SKILL.md and asks the user to provide the key.
  3. The user posts the BrowserAct API key in the conversation.
  4. The credential becomes part of chat history, logs, telemetry, or retained agent context.
  5. A party with access to one of those surfaces obtains the key.
  6. The exposed key is reused against BrowserAct services until it is revoked or expires.

I

...[truncated 440 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the instruction to ask users to provide API keys through chat.
  • Instruct users to configure BROWSERACT_API_KEY locally using an environment variable or an approved secret manager.
  • Ensure the agent only checks whether the variable exists and never prints, echoes, stores, or requests its value.
  • Add explicit guidance stating that API keys must not be pasted into conversations.
  • Recommend immediate key revocation and rotation if a credential has already been shared through chat.
  • Where supported, use narrowly scoped credentials with quota limits and short expiration periods.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/amazon_product_api.py:102
Finding

Runtime error message advises users to provide an API key in chat

Content
View full analysis

Vulnerability Details

File Location: scripts/amazon_product_api.py:102-105
Vulnerability Type: Credential exposure through unsafe runtime guidance
Risk Level: Medium

Vulnerable Code

python
if not api_key:
    print("\n[!] ERROR: BrowserAct API Key is missing.", flush=True)
    print("Please follow these steps:", flush=True)
    print("1. Go to: https://www.browseract.com/reception/integrations", flush=True)
    print("2. Copy your API Key.", flush=True)
    print("3. Set it as an environment variable (BROWSERACT_API_KEY) or provide it in the chat.", flush=True)
    sys.exit(1)

Technical Analysis

The runtime error explicitly presents posting the API key in chat as an alternative to configuring an environment variable. This expands credential exposure beyond what is required for the script to operate. The implementation already reads the key securely from BROWSERACT_API_KEY, so conversational disclosure provides no necessary technical capability.

The script does not print the key or send it to an undeclared destination. It uses the key as a Bearer token for requests to the documented BrowserAct API. Nevertheless, the error message can induce users to disclose a reusable credential into systems where messages may be retained or logged.

Attack Path

  1. The script is run without BROWSERACT_API_KEY.
  2. The error message tells the user that the key may be provided in chat.
  3. The user follows that guidance and submits the credential to the agent.
  4. The credential is retained in conversation history, logs, telemetry, or contextual state.
  5. An unauthorized party with access to those records extracts the key.
  6. The party uses it to make BrowserAct API requests within the key's assigned permissions.

Impact Assessment

Exposure may permit unauthorized BrowserAct API use, quota depletion, unexpected charges, and access to workflows or other resources authorized for the key ...[truncated 220 chars]

Remediation
View remediation

Remediation Suggestions

Replace the unsafe message with guidance that only permits local secret configuration, for example:

python
if not api_key:
    print(
        "ERROR: Set BROWSERACT_API_KEY using your local environment "
        "or an approved secret manager. Do not paste API keys into chat.",
        flush=True,
    )
    sys.exit(1)

Additionally:

  • Never accept API keys through command-line arguments, because they may appear in shell history and process listings.
  • Do not include credential values in exceptions, diagnostic output, or request logs.
  • Use a secret manager where available and grant the key only the permissions required to run the declared workflow.
  • Rotate any key previously disclosed through chat or another logged channel.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/amazon_product_api.py (reported line 92)May include surrounding context.

python
return None

if __name__ == "__main__":
    # Get API key from environment variable
    api_key = os.getenv("BROWSERACT_API_KEY")
    
    if len(sys.argv) < 2:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises executable capabilities that rely on environment secrets and outbound network access, but it does not declare a corresponding tool/permission scope. That mismatch weakens least-privilege controls and can cause an agent runtime to invoke code or access secrets without clear policy boundaries, increasing the risk of unintended data exposure or unauthorized external requests.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/amazon_product_api.py (reported line 16)May include surrounding context.

python
# API Configuration
# Amazon Product API Template ID
TEMPLATE_ID = "77670107419143475"
API_BASE_URL = "https://api.browseract.com/v2/workflow"

def run_amazon_product_task(api_key, keywords, brand="Apple", pages=1, language="en"):
    """

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The script sends user-supplied search parameters and an authorization bearer token to a third-party external service, which is a real data transmission boundary. In the context of an agent skill, this is security-relevant because users may not expect their prompts, brands, languages, or operational metadata to be forwarded off-platform, and the code lacks explicit consent, validation, timeout controls, or minimization safeguards.

Content

Scanner excerpt · scripts/amazon_product_api.py (reported line 36)May include surrounding context.

python
# 1. Start Task
    print(f"Starting Amazon Product search task for keywords: {keywords}", flush=True)
    try:
        response = requests.post(f"{API_BASE_URL}/run-task-by-template", json=payload, headers=headers)
        res = response.json()
    except Exception as e:
        print(f"Error: Connection to API failed - {e}", flush=True)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown specifies a language parameter with a default of en, which imposes a locale choice unless the user overrides it. The policy requires avoiding forced language or locale settings unless the skill offers explicit choice or clearly justified locale constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The comments and assignments explicitly override stdout and stderr encoding to UTF-8 for all executions. This imposes a locale/output encoding policy unconditionally rather than offering a user choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.