Back to skill

Security audit

Offsite Signal Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed SEO analysis helper, with bounded notes around sensitive analytics data, optional connector commands, and user-confirmed memory saves.

Before installing, be aware that the skill may handle private analytics exports or server logs; share only the needed slice and redact user identifiers where possible. Treat the python connector references as optional and use them only if those local scripts are available from a reviewed source. Memory saves should remain user-approved and limited to monitoring summaries and follow-up items.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/link-quality-rubric.md (reported line 45)May include surrounding context.

md
|---------|-----------------|--------------|---------|
| Strong mid-size SaaS | 1,200 referring domains, 72% dofollow, avg DR 38, 35% brand anchors, 8% exact match, 3% toxic estimate | None material | Continue current strategy. |
| At-risk competitive niche | 800 referring domains, 92% dofollow, avg DR 18, 42% exact match, 30% topical relevance, 18% toxic estimate | Over-optimized anchors, low relevance, unnatural velocity | Review toxic links, diversify anchors, slow acquisition. |
| Healthy new site | 45 referring domains, 65% dofollow, avg DR 28, 40% brand anchors, 5% exact match, +8/month velocity | Low volume only | Do not judge by mature-site volume; scale carefully while preserving quality. |

## 3. Competitive Link Gap Analysis

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes this skill as analyzing backlinks or AI-referral traffic, but the contract also instructs it to write monitoring deliverables, persist handoff summaries under memory/monitoring/, and promote items to memory/open-loops.md. Those persistence and workflow-management actions are not necessary to perform the analysis itself and are not justified by the stated user-facing purpose of an off-site signal analyzer.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The stated purpose is backlink analysis and AI-referral analysis, but this line introduces GDELT-based brand mention monitoring as an 'unlinked-citation complement.' Monitoring news mentions is a distinct off-site reputation/PR capability rather than backlink profiling, anchor analysis, toxic-link review, or AI-referral isolation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says ai-referrals mode isolates AI-assistant referral sessions in GA4/GSC/logs and reports trends, landing pages, and conversion. This line adds Tavily-based searching of AI answer engines to check whether synthesized answers cite the domain, which is a different capability from analyzing the user's own referral analytics and is not clearly justified by the declared mode.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.