Back to skill

Security audit

Amazon Review Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently fetches Amazon reviews through a disclosed paid Reveyes API workflow and generates local analysis reports with explicit cost and credential safeguards.

Before installing, understand that this skill uses your Reveyes API key and can spend Reveyes points when you explicitly run fetch with a confirmed limit. Keep the API key in the environment or an explicit env file, review the generated plan before paid calls, and avoid sharing raw run directories because they can contain reviewer names, profile URLs, task IDs, and raw review text even though the default public HTML report omits some of those fields.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.