Back to skill

Security audit

Amazon Pricing Intelligence

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language Amazon pricing advice skill with no executable code, hidden data access, or persistence.

Install this if you are comfortable using a Chinese-language Amazon seller pricing assistant and sharing the product costs, prices, sales volume, FBA fees, and competitor links needed for analysis. Verify any Amazon fee and benchmark numbers against current Amazon documentation before relying on pricing recommendations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description, commands context, and example dialogue are presented entirely in Chinese, which implies a fixed language experience. Under the policy, locale or language restrictions should either provide user opt-in/choice or be explicitly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description embeds multiple generic trigger phrases such as 'amazon pricing', '定价策略', and 'pricing optimization' without clear scoping to a narrow workflow. Broad triggers can cause unintended activation in unrelated conversations, which may lead the agent to collect business-sensitive pricing, cost, and sales data when the user did not explicitly intend to invoke this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description and the rest of the skill content are written entirely in Chinese, while also advertising support for multiple international markets. There is no indication that users may choose another language or that Chinese-only usage is an intentional, justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file is written entirely in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description is written entirely in Chinese, which can impose a language/locale constraint on users without offering a choice or explaining that the skill is intended only for a Chinese-speaking audience. This matches the policy concern for language or locale restrictions expressed in natural language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.