Back to skill

Security audit

SEO 2026 - AI Era Content Engine

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal SEO writing and research skill, with the main caveat that its trigger wording is broad enough to activate during ordinary content-writing requests.

Install if you want SEO-oriented content help. For ordinary writing, be explicit when you do not want keyword research, competitor analysis, web browsing, or SEO optimization applied.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description advertises very broad triggers such as writing blog posts, keyword research, SEO optimization, improving rankings, and building authority. In an agent system, this can cause the skill to activate for many generic content requests, increasing the chance it runs unexpectedly, performs web actions, and influences outputs outside the user's intended scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The Quick Start section uses vague trigger phrases like 'write a blog post about X' and 'do keyword research for X' without boundaries or confirmation steps. This makes the skill easier to invoke accidentally for ordinary writing tasks, which may lead to unnecessary browsing, competitor analysis, and SEO shaping when the user did not ask for those actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.