Back to skill

Security audit

amazon-selection-agent

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Amazon product-research skill that uses public web research and saves a Markdown report, with no credential use, account actions, or hidden execution found.

Install this if you want a Chinese-language Amazon product-research workflow that performs substantial public web research and writes a local Markdown report. Avoid providing confidential seller backend data or credentials; review the saved report path and contents if product ideas, costs, or supplier assumptions are sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The skill explicitly requires writing a full Markdown report to a file even though the capability described is primarily analytical. Unnecessary file creation expands the agent's side effects, can persist sensitive user-provided business inputs or scraped data, and creates a mismatch between user expectations and actual behavior.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The trigger phrases include broad natural-language requests such as '帮我看看这个品类', '分析这个产品', and '算一下利润', which are common in ordinary conversation. This can cause the skill to activate in contexts the user did not intend, leading to over-collection via web searches/fetches and possibly file-writing side effects defined elsewhere in the skill.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill mandates writing a full report to disk and only says to provide the file path after completion, without prior disclosure or consent about storage. That creates a transparency and data-handling issue because user inputs, product targets, cost assumptions, and collected research may be persisted unexpectedly.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The template mandates Chinese-language output across the full report and user-facing summary without offering locale selection or honoring user preference. In a broad product-research skill, this can cause misleading or unusable output for users expecting another language, increasing the risk of misunderstood business recommendations, data interpretation errors, and poor downstream decisions.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.