Back to skill

Security audit

Geo Content Optimizer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed marketing content optimizer with limited local memory use and no hidden execution or destructive behavior found.

Before installing, be aware that the skill can consult local entity memory for brands, people, or products mentioned in content, and it may save or promote content summaries when confirmed. Review outputs for factual accuracy because GEO recommendations include estimates and platform heuristics, not guaranteed citation outcomes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest defines capabilities and package limits but does not declare any activation triggers, routing constraints, or invocation boundaries, so the skill's eligibility to run is left to broader platform behavior. For a marketing/content optimization skill, this can cause over-broad activation on loosely related prompts, increasing the chance that the skill influences responses outside its intended scope and exposes users to unintended prompt steering or content manipulation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.