amazon-keyword-research

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The bash script scripts/research.sh is susceptible to Python code injection. It constructs a Python command string by directly interpolating the shell variable $KEYWORD into single quotes within a python3 -c call. A maliciously crafted keyword containing a single quote can escape the string literal and execute arbitrary Python code in the skill's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external search results and user keywords without sufficient sanitization.
  • Ingestion points: User keywords and competitive data fetched from Amazon and Google Trends as described in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to distinguish external data from core instructions.
  • Capability inventory: Local script execution and network search capabilities.
  • Sanitization: The skill lacks logic to escape or validate content retrieved from external sources before presenting it to the agent or user.
  • [EXTERNAL_DOWNLOADS]: The skill fetches autocomplete suggestions and market trends from Amazon's official APIs and Google Trends. These are well-known and appropriate services for the skill's keyword research purpose.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 02:42 PM
Security Audit — agent-trust-hub — amazon-keyword-research