Back to skill

Security audit

Content Writer

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only SEO writing skill with disclosed content, analytics, optional connector, and opt-in memory behaviors that fit its stated purpose.

Before installing, understand that this skill can use supplied SEO data, competitor examples, and optional connected analytics/search-console tools to draft or refresh content. Review any republishing, index-push, cache, or sitemap recommendations before applying them to a live site, and only allow memory saves when you want future sessions to retain the summary.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

The skill explicitly authorizes autonomous choices in several cases, including changing mode, selecting competitors, and applying republish-date treatment without confirmation. In a content/publishing workflow, this can cause unintended actions or materially alter outputs based on inferred or estimated data, reducing user control and increasing the chance of incorrect publishing recommendations.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
**Continue silently (never stop for):**
- Missing analytics/ranking history — score decay from on-page signals (dated claims, broken links, stale stats), label findings Estimated, and proceed.
- A "refresh" request with no existing URL — note the mismatch once and run `--mode new`.
- Which republish-date treatment to apply — follow the Step 8 thresholds without asking.
- Which competitor pages to deep-dive when several are named — pick the top-ranking 3 and proceed.

## Reference Materials

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The display name, summary, and description include Chinese-language text alongside English, but the skill does not state that language selection is optional or user-driven. This can violate a language/locale policy when a skill presents a specific language by default without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:63