Competitor Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a coherent instruction-only competitor-analysis skill, with the main things to notice being optional SEO/analytics data use, persistent memory summaries, and some linked workflow docs outside the package.

This skill appears safe to install as an instruction-only competitor-analysis workflow. Before using it, decide what analytics or SEO-tool data you are comfortable sharing, review any proposed memory saves, and consider checking the linked GitHub support documents because they were not fully included in the reviewed package.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI06: Memory and Context Poisoning
Low
What this means

Competitor facts or strategy notes saved to memory may influence future agent work and could preserve sensitive or stale business assumptions.

Why it was flagged

The skill is designed to persist analysis outputs and strategy decisions into reusable memory files.

Skill content
Promotes: durable competitor facts, keyword priorities, entity candidates, and pending strategy decisions to `memory/hot-cache.md`, `memory/open-loops.md`, and `memory/research/`.
Recommendation

Review saved summaries before approving them, keep sensitive strategy details out of shared memory when possible, and periodically remove stale competitor notes.

#
ASI04: Agentic Supply Chain Vulnerabilities
Low
What this means

The skill may rely on linked documents outside the packaged files, which could change independently of the reviewed artifact.

Why it was flagged

Some referenced workflow/state documents are external GitHub links and were not included in the provided artifacts, so their exact instructions were not fully reviewable here.

Skill content
Reads: goals, market inputs, tool data, and prior strategy from [CLAUDE.md](https://github.com/aaron-he-zhu/seo-geo-claude-skills/blob/main/CLAUDE.md) and the shared [State Model](https://github.com/aaron-he-zhu/seo-geo-claude-skills/blob/main/references/state-model.md) when available.
Recommendation

Review or pin the linked supporting documents before relying on them for persistent workflows or shared state conventions.

#
ASI03: Identity and Privilege Abuse
Info
What this means

If connected to analytics or SEO tooling, the analysis may use private traffic, ranking, or market data.

Why it was flagged

The skill can incorporate analytics/tool data or user-provided site metrics, which may be private business information, although no credentials are required by the package metadata.

Skill content
Optional integrations: ~~SEO tool, ~~analytics, ~~AI monitor. Without tools, ask for competitor URLs, your site metrics, and industry context.
Recommendation

Only provide or connect the data needed for the analysis, and confirm any analytics or SEO-tool access is limited to the intended accounts and properties.