Aeo

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed website audit and optimization helper, with some normal caution needed because it runs an external npm package and can make site-file changes when asked.

Before installing, confirm you are comfortable with the skill running @ainyc/aeo-audit through npx and making confirmed changes to website-facing files such as llms.txt, llms-full.txt, and robots.txt. Use fix or monitor mode only when you intend edits or local audit-history persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
Allowing the skill to infer mode from broad user intent without strict trigger boundaries can cause it to perform a more invasive action than the user clearly requested, especially around 'fix' or 'monitor' behaviors. In this skill, different modes can edit files or persist history, so ambiguous inference increases the risk of unintended state-changing operations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal