Back to skill

Security audit

amazon-listing-upload

Security checks across malware telemetry and agentic risk

Overview

This documentation-only Amazon Seller Central helper is mostly coherent, but it includes ready-to-use supplement and advertising guidance that can create account or compliance risk.

Review supplement listing language and advertising-related sections carefully before installing. Do not let an agent publish listings, change prices or inventory, create shipments, dispose of inventory, or enter customer shipping data without explicit approval; get separate compliance review before using any supplement health claims or keywords in a live Amazon listing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
This is a true issue. The file asserts that no medical claims are made, but the listing copy contains supplement claims such as liver detox, improved digestion, metabolic optimization, bile production support, bloating relief, and liver cell renewal. In the Amazon supplements context, these are policy-sensitive health claims that can cause account enforcement, listing removal, or regulatory exposure because the example is framed as a best-practices template users may copy directly.

Intent-Code Divergence

Low
Confidence
85% confidence
Finding
This is a genuine scope/control issue. The document markets itself as a best-practices example for the skill, but includes guidance outside the stated skill boundaries by recommending advertising strategy despite the manifest explicitly excluding Amazon Advertising. That mismatch can mislead downstream agents or users into relying on unsupported guidance and weakening trust in the skill's boundaries.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
This is a true vulnerability in the form of unauthorized capability expansion. The file includes PPC auto/manual campaign planning and optimization advice even though the skill description explicitly says it is not for Amazon Advertising. In agent settings, examples often shape model behavior more strongly than manifests, so this content can induce the agent to provide disallowed advertising assistance.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This workflow gives detailed supplement-listing guidance, including example health-support claims and backend keyword examples, without warning users about Amazon policy, FDA/FTC rules, or the risk of disease-treatment and unsubstantiated structure/function claims. In this skill context, that omission is more dangerous because the content is operational and ready to use, making it easy for users to publish noncompliant supplement listings that can trigger listing suppression, account enforcement, or consumer deception.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.