SEO/GEO Page-Level Keyword Optimizer

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a coherent SEO keyword-optimization skill that uses Ahrefs as expected, but users should understand that page and competitor data may be sent to Ahrefs.

Install this only if you intend to use Ahrefs-backed SEO analysis. Avoid using it with confidential, unpublished, internal, or embargoed URLs unless your organization approves sending page, keyword, and competitor information to Ahrefs, and use a scoped Ahrefs API key where possible.

SkillSpector (2)

By NVIDIA

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broad enough that an agent may invoke it for many generic SEO or page-editing tasks without the user explicitly consenting to Ahrefs-backed competitive analysis or external data use. In an agentic environment, over-broad invocation increases the chance of unnecessary tool execution, data sharing, and unintended content changes, even though the skill itself is not overtly malicious.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow requires sending target page URLs, competitor URLs, and derived keyword intelligence to Ahrefs services, but the skill does not clearly disclose this external transmission at the point where inputs are requested. This creates a privacy and data-governance risk because users may provide internal, embargoed, or sensitive URLs without understanding that third-party processing is involved.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal