Back to skill

Security audit

Amazon 卖家指南针

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Amazon seller research skill that uses public web research and saves a local Markdown report, with no evidence of hidden exfiltration, credential use, or destructive behavior.

Install only if you want an Amazon/FBA research assistant that performs extensive public web research and creates a local Markdown report. Avoid providing private Seller Central data, credentials, or confidential supplier terms unless you are comfortable with them appearing in the saved report, and ask the agent to confirm the output path before writing if that matters to your workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill mandates writing a full analysis report to a Markdown file, which expands behavior from conversational analysis into persistent local data storage. This creates an unannounced data-handling surface where potentially sensitive user inputs, product ideas, links, cost assumptions, or business strategy may be stored on disk and exposed to other tools, users, or later sessions.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger phrases are broad, natural-language requests such as '分析这个产品' or '这个能不能做', which can match ordinary conversation outside the intended Amazon-selling context. Over-broad invocation can cause the skill to activate unexpectedly, leading to unwanted web access, report generation, or business analysis when the user did not intend to use this specialized tool.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill requires saving the generated report to disk but does not disclose this persistence behavior in the user-facing description or trigger text. Users may share commercially sensitive information assuming an ephemeral chat, while the skill silently creates a durable artifact that may be retained, synced, or accessed later.

Missing User Warnings

Low
Confidence
94% confidence
Finding
The template explicitly instructs the skill to write a complete report to a file, but it does not require user consent, disclose that a file will be created, or constrain where the file may be written. In an agent context, silent filesystem writes can surprise users, overwrite existing artifacts, or create unintended data retention, even if the content itself is benign business analysis.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The document hard-codes Chinese as the required output language for the full report without indicating that this depends on user preference. While not a classic security flaw, forced locale behavior can reduce transparency and user comprehension, which increases the chance that important business or file-write actions are not fully understood by users operating in another language.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.