Amazon Seasonal Planner

Security checks across malware telemetry and agentic risk

Overview

This is a content-only Amazon seasonal planning guide; its broad triggers and Chinese-only text are usability considerations, not security concerns.

Installers should treat this as a planning reference. Because the advice can affect inventory purchases, pricing, and ad spend, verify current Amazon deadlines, FBA fees, promotion rules, margins, and inventory assumptions before acting on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list is broad and includes generic seasonal-planning terms such as 'christmas', 'seasonal planning', and 'holiday season', which can cause the skill to activate in ordinary conversations that are not specifically about this tool. This increases unintended invocation risk, causing response hijacking or user confusion, though it does not directly enable code execution or data exfiltration.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill is presented entirely in Chinese and does not offer a language choice, which can force unexpected language switching for users operating in other languages. This is primarily a safety and usability issue because it can mis-handle user intent, reduce comprehension of business guidance, and make incorrect operational decisions more likely.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal