Back to skill

Security audit

amazon-listing-upload

Security checks for vulnerabilities and agentic risk

Overview

This Amazon Seller Central guide has no executable code, but it contains risky supplement listing copy and advertising guidance outside its stated scope.

Review regulated categories carefully before installing or using this skill. Do not publish the supplement example as-is, verify all health claims against current Amazon, FDA, and FTC requirements, and avoid using this skill for PPC or advertising workflows despite the example text.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file asserts 'No medical claims made' while the listing repeatedly claims detoxification, improved digestion, metabolism benefits, bloat relief, and liver cell renewal. In a supplements-selling context, this is dangerous because it can cause the agent to generate noncompliant health claims while falsely signaling that the content is compliant, increasing the risk of policy violations, listing suspension, or regulatory exposure.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/category-requirements.md (reported line 7)May include surrounding context.

md
## Category Overview

### Open Categories (No Approval Needed)
- Home & Kitchen
- Sports & Outdoors
- Tools & Home Improvement

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example provides ready-to-reuse supplement marketing copy containing health-effect claims without a strong user-facing warning that the content may be noncompliant and must be legally/policy reviewed before use. Because this is an example file inside a listing-management skill, users and agents are likely to copy it verbatim, propagating risky supplement claims into live listings.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example includes PPC/Advertising launch steps even though the skill metadata explicitly says it is not for Amazon Advertising. This creates a scope-boundary failure: downstream agents or users may treat the example as authorized guidance and perform ad-related actions outside the skill’s declared safety and capability envelope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template headings and field labels are written in Chinese throughout, which effectively forces a specific language/locale for users filling out the skill artifact. The file does not offer an alternative language option or explain that the template is intended only for a Chinese-speaking or region-specific workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Line L043 says 'local language needed' for the JP marketplace, which is a natural-language locale requirement presented as a constraint without offering user choice or clarifying that this is an external Amazon platform requirement. Under the policy, forced language or locale requirements should be either optionalized or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file explicitly fixes the marketplace to "Amazon.com (US)", which is a locale-specific constraint in natural language. There is no indication that the user can choose a different locale or that this example is limited to a US-only compliance context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file describes a step where the user provides customer shipping information to Amazon, which affects third-party customer data. The surrounding instructions do not warn that personal shipping data will be shared with Amazon or advise the user to ensure they are authorized to use that data for fulfillment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The statement 'Japanese language materials preferred' expresses a locale/language preference in natural language. Under the policy, forcing or directing a specific language without explicit user choice or a clearly documented justification can be a policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.