Back to skill

Security audit

geo-prospect

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local CRM helper for GEO prospects, with persistent record updates that match its stated purpose.

Install only if you want a local CRM-style record keeper for GEO sales work. Use explicit /geo prospect commands, and be aware it can create or update prospect records, notes, audit paths, and deal values in ~/.geo-prospects/.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough that ordinary conversation about prospects, clients, leads, or CRM activity could invoke the skill unintentionally. Because the skill has Write and Bash capabilities and performs persistent modifications to CRM state, accidental activation could create, alter, or save business records without the user explicitly intending to run this skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.