Amazon Brand Accelerator

PassAudited by VirusTotal on May 3, 2026.

Overview

Type: OpenClaw Skill Name: amazon-brand-accelerator Version: 1.0.3 The bundle is a comprehensive strategic guide and toolset for Amazon brand building. The Python script (scripts/brand-accelerator.py) is a well-structured utility for scoring brand readiness and generating roadmaps based on provided data, containing no risky system calls or network activity. The documentation (SKILL.md, README.md, and references/) provides educational content and templates without any evidence of prompt injection or malicious instructions.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Following the plan without review could spend money, launch paid programs, or affect marketplace listings.

Why it was flagged

The checklist includes paid trademark/Vine actions and Project Zero self-removal setup. These are business-impacting platform actions, but the artifacts frame them as manual checklist steps rather than automatic execution.

Skill content
支付申请费用(按类别计费) ... 支付Vine计划费用(通常$200/ASIN) ... 审核通过后配置自助移除权限
Recommendation

Require explicit human approval for payments, ad launches, Brand Registry submissions, and enforcement/removal actions; verify current Amazon and trademark-office rules first.

What this means

If credentials or privileged account details are shared with an agent unnecessarily, seller-account access could be exposed.

Why it was flagged

The workflow requires access to privileged seller or Brand Registry accounts and brand-rights-holder information. No artifact shows credential capture or storage.

Skill content
登录亚马逊卖家/供应商账户 ... 填写品牌信息 ... 添加其他品牌权益持有者信息
Recommendation

Log in through official sites yourself, do not paste passwords, cookies, or session tokens into the agent, and use least-privilege account roles where possible.

What this means

Business performance, order, advertising, and customer-insight data could be exposed if shared too broadly.

Why it was flagged

The KPI framework asks users to collect detailed business, order, review, and advertising data. This is expected for brand analysis, but it can be sensitive if pasted into agent context or stored for reuse.

Skill content
本季度Brand Analytics全量数据导出 ... 订单数据(销售量、复购率、退货率) ... 品牌广告投放数据(花费、效果)
Recommendation

Share only the minimum necessary data, anonymize or aggregate where possible, and avoid uploading full exports unless you trust the environment.

What this means

Users have less provenance information for deciding whether to trust or run the included helper script.

Why it was flagged

The package has limited provenance and includes a helper script despite being described as instruction-only. The reviewed visible code is purpose-aligned and static scan signals are clean, so this is a review-context note rather than a behavioral concern.

Skill content
Source: unknown; Homepage: none ... No install spec — this is an instruction-only skill ... 1 code file(s): scripts/brand-accelerator.py
Recommendation

Treat the skill as unofficial, review the included script before running it, and prefer verified sources for legal or marketplace operations.

What this means

Users might overtrust the guidance as official Amazon advice.

Why it was flagged

The script uses an official-sounding author label while the registry source is unknown and the package metadata lists a different author. This could lead users to over-assume Amazon affiliation, though no malicious behavior is shown.

Skill content
Author: Amazon Brand Team
Recommendation

Do not assume the skill is endorsed by Amazon; verify platform rules, fees, and legal steps with official documentation or qualified professionals.