Back to skill

Security audit

geo-platform-optimizer

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent GEO audit/report generator, with network checks and report writing that fit its stated purpose.

Before installing, use this skill for user-specified GEO or AI-search platform audits and confirm the target domain. Treat recommendations involving account setup, public posts, Wikidata/Wikipedia edits, Business Profile changes, sitemap submission, or IndexNow implementation as actions requiring separate user approval and review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description is very broad and does not define when the skill should or should not be invoked. In an agent environment, this can cause the skill to activate for loosely related SEO, content, analytics, or website-audit tasks, expanding access to powerful tools like Bash, WebFetch, and Write beyond the user’s likely intent.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The operational instructions explain how to execute the skill but still do not place firm boundaries on activation or target scope. Because the skill directs collection of target URLs, platform checks, and report generation, an agent may over-apply it to broad site analysis tasks and perform unnecessary external fetching or file writes without a clearly constrained use case.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.