amazon-listing-upload

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a coherent instruction-only Amazon Seller Central guide, but users should manually approve any real account changes, listings, shipments, or customer-data entries.

Install only if you want an agent to help with Amazon Seller Central workflows. Keep control of the browser session, verify every listing, price, inventory count, shipment, removal order, and customer-data entry before submission, and do not let the agent make final account changes without your approval.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI02: Tool Misuse and Exploitation
Medium
What this means

If followed without review, the agent could submit an incorrect listing, price, inventory value, or other account change.

Why it was flagged

The skill can guide an agent through final Seller Central submission steps. This is purpose-aligned, but it can publish or change business-facing Amazon listing data.

Skill content
### Submit Listing
1. Click "Save and Finish"
2. Wait for submission confirmation
Recommendation

Require explicit user confirmation before any Seller Central submit, save, shipment, pricing, inventory, removal, or fee-incurring action.

#
ASI03: Identity and Privilege Abuse
Medium
What this means

Actions taken in the browser may occur under the user’s seller identity and could affect listings, inventory, shipments, or charges.

Why it was flagged

The workflow assumes access to a real Amazon Seller Central account. That access is expected for this skill, but it is privileged business account authority.

Skill content
Before starting, ensure you have:
- [ ] Seller Central account (Professional plan)
Recommendation

Use the least-privileged Seller Central account/session available and supervise all account-changing steps.

#
ASI07: Insecure Inter-Agent Communication
Low
What this means

Customer names/addresses could be handled during fulfillment workflows.

Why it was flagged

The skill describes entering customer shipping information into Amazon for fulfillment. This is expected for MCF, but it is a sensitive data flow to a third-party provider.

Skill content
Create MCF order
3. Enter customer shipping info
4. Amazon ships from FBA inventory
Recommendation

Only enter customer shipping data when necessary for a user-approved fulfillment task, and verify the destination is the legitimate Amazon Seller Central site.