Back to skill

Security audit

Keyword Research

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal SEO keyword-research skill, but users should be aware it may use connected marketing data and save research summaries to memory.

Install only if you are comfortable with the agent using any connected SEO or Search Console data for keyword research and saving summaries into the host memory files. For sensitive launches, private strategy, or client data, ask the agent not to persist results or manually review the generated memory entries afterward.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The instructions explicitly include a competitor-gap analysis prompt even though the skill metadata says this skill is not for competitor-relative coverage gaps and should defer to another skill. This creates a scope-confusion vulnerability: an agent may execute the wrong workflow, use inappropriate data sources, or bypass intended routing controls, leading to incorrect outputs and policy violations.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The detailed instructions explicitly include a competitor-gap analysis prompt even though the manifest says this skill is not for competitor-relative coverage gaps and directs users to a different skill. This creates scope drift that can cause the agent to perform tasks outside its declared boundaries, leading to incorrect tool selection, policy bypass of skill routing, and potentially unintended access or analysis against competitor datasets.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The Advanced Usage section broadens the skill's operational scope beyond the manifest by presenting competitor gap analysis as supported functionality. In an agentic system, mismatched scope definitions are dangerous because they can override routing expectations, cause misuse of connected data sources for unintended analysis, and blur security boundaries between narrowly scoped skills.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to write and promote outputs into persistent memory files without any explicit user-facing notice or confirmation. In hosts where memory is shared across sessions or later influences agent behavior, this can cause unauthorized persistence, context poisoning, or accidental retention of sensitive business data provided during keyword research.

Vague Triggers

Medium
Confidence
71% confidence
Finding
Broad invocation phrases can cause the wrong skill to trigger on loosely related user requests, which may lead the agent to perform unintended actions such as querying connectors or writing research artifacts to memory. In an agent-skill environment, overbroad routing is a security-relevant control failure because it expands the circumstances under which the skill can access external data sources and persist outputs.

Missing User Warnings

Low
Confidence
85% confidence
Finding
The skill explicitly writes durable outputs to memory locations, but the markdown does not provide a clear user-facing notice or consent checkpoint before persistence. This can cause unintended retention of user-provided business data, research strategy, or connector-derived information, which is a privacy and data-governance risk in shared or long-lived agent environments.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.