Back to skill

Security audit

Geo Content Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This GEO marketing skill is mostly purpose-aligned, but it asks for persistent memory updates and an external Tavily probe that are not clearly covered by its lite manifest.

Review this before installing if your content includes confidential launches, private URLs, client names, or sensitive campaign terms. Use it only where memory writes are acceptable, confirm exactly what will be saved, and avoid running the Tavily probe unless you are comfortable sending the query or URL to that external service.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:38
Finding

Persistent State Writes Are Not Declared in the Capability Manifest

Content
View full analysis
.md` (per the [entity-geo handoff schema](../../../references/entity-geo-handoff-schema.md)) to populate `display_name`, `description_short`, `ai_resolution_status` and decide whether disambiguation boilerplate is needed. If the profile is missing or stale (>90 days), declare `DONE_WITH_CONCERNS` and recommend `entity-registry` as an open loop. - **Writes**: a user-facing content, metadata, or schema deliverable plus a reusable summary that can be stored under `memory/content/`. - **Promotes**: approved angles, messaging choices, missing evidence, and publish blockers to `memory/hot-cache.md` and `memory/open-loops.md`; propose durable decisions as pending-decision items. ``` `SKILL.md:82-84`: ```markdown ## Save Results On user confirmation, save to `memory/content/YYYY-MM-DD-.md` — see [Skill Contract](../../../references/skill-contract.md) §Save Results Template. ``` ### Technical Analysis The package manifest declares only `inline-delivery` and `canonical-state-read`. The Skill instructions nevertheless describe writes to: - `memory/content/` - `memory/hot-cache.md` - `memory/open-loops.md` This creates a discrepancy between the package's declared capability ceiling and its documente ...[truncated 2294 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:54
Finding

Undeclared External Connector Execution Can Transmit User Queries Outside the Local Environment

Content
View full analysis
" --answer --limit 10` runs that citability test against a real AI answer engine, no key needed — check whether the synthesized answer cites your URL/domain and where the page ranks among the scored sources. This is **Measured** for Tavily's own layer and an **Estimated proxy** for ChatGPT/Perplexity/Google AI Overviews (different indexes, different retrieval). Re-run after shipping changes for a minutes-scale citability read; unprompted surfacing stays week-scale per the paragraph above. See [scripts/connectors/README.md](../../../scripts/connectors/README.md). ``` ### Technical Analysis The Skill recommends invoking a Python connector outside the supplied package: ```text ${CLAUDE_PLUGIN_ROOT}/scripts/connectors/tavily.py ``` The command submits a target query to Tavily, described as a real AI answer engine. Consequently, query text and potentially a target URL or ...[truncated 2579 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.