Back to skill

Security audit

Amazon Product Search Api Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it encourages users to give an API key directly to the agent and sends Amazon search details to BrowserAct with limited consent guidance.

Install only if you are comfortable sending Amazon search terms and brand or market-research parameters to BrowserAct. Configure BROWSERACT_API_KEY through your environment or an approved secret manager, do not paste the API key into chat, and rotate any key that was previously shared in a conversation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:31
Finding

API Credential Disclosure Encouraged Through Agent Conversation

Content
View full analysis
"Since you haven't configured the BrowserAct API Key, please visit the [BrowserAct Console](https://www.browseract.com/reception/integrations) to get your Key." ``` `scripts/amazon_product_search_api.py:97-102`: ```python if not api_key: print("\n[!] ERROR: BrowserAct API Key is missing.", flush=True) print("Please follow these steps:", flush=True) print("1. Go to: https://www.browseract.com/reception/integrations", flush=True) print("2. Copy your API Key.", flush=True) print("3. Provide it to me or set it as an environment variable (BROWSERACT_API_KEY).", flush=True) sys.exit(1) ``` ### Technical Analysis The Skill documentation directs the Agent to ask the user to provide the BrowserAct API key, while the executable script explicitly presents providing the key “to me” as an alternative to configuring an environment variable. This encourages users to disclose a reusable credential through the Agent conversation. The script only requires access to `BROWSERACT_API_KEY` through its process environment. The Agent does not need to read or receive the plaintext credential in conversation. Asking for it therefore exceeds the minimum access necessary for the declared Amazon product-search functionality. Credentials entered into a conversation may be retained in chat history, Agent execution traces, diagnostic records, or other logging systems. The reviewed code does not itself transmit the key to an undeclared endpoint: it uses the key as a Bearer token for the declared H ...[truncated 1474 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares executable capabilities via Python and an API key requirement, and its workflow clearly depends on external network access, but it does not define any explicit tool scope such as allowed tools or permissions. That weakens least-privilege boundaries and can allow broader-than-expected execution or data access when the skill is invoked, especially in agent environments that rely on declared scope for enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says the agent should proactively apply this skill across a very broad set of common shopping, monitoring, cataloging, and research requests. That creates a real risk of unintended invocation, causing user queries and business research inputs to be sent to a third-party API without sufficiently specific user intent or consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs use of a third-party BrowserAct API to process Amazon search inputs, but it does not clearly warn that search terms, brands, and market-research parameters will be transmitted externally. This can lead to inadvertent disclosure of potentially sensitive commercial intent, competitive research plans, or proprietary product lists.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/amazon_product_search_api.py (reported line 15)May include surrounding context.

python
# API Configuration
TEMPLATE_ID = "77809217106347580"
API_BASE_URL = "https://api.browseract.com/v2/workflow"

def run_amazon_product_search_task(api_key, keywords, brand="Apple", limit=50, language="en"):
    headers = {"Authorization": f"Bearer {api_key}"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/amazon_product_search_api.py (reported line 32)May include surrounding context.

python
# 1. Start Task
    print(f"Start Task", flush=True)
    try:
        res = requests.post(f"{API_BASE_URL}/run-task-by-template", json=payload, headers=headers).json()
    except Exception as e:
        print(f"Error: Connection to API failed - {e}", flush=True)
        return None

Static analysis

No suspicious patterns detected.