Back to skill

Security audit

seo-backlinks

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent SEO backlink-audit guide that uses expected SEO data sources and does not show hidden, destructive, or credential-stealing behavior.

Before installing, understand that this skill may use third-party SEO services and crawlers, so analyzed domains and backlink data can be sent to those tools. Treat toxic-link and disavow recommendations as review inputs, not automatic actions, and check that any optional Moz, Bing, or DataForSEO credentials are configured only where you intend to use them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Low
Confidence
90% confidence
Finding
The skill hard-codes a mandatory upsell/promotion for an unrelated command after every analysis. This is an instruction-integrity issue because it can steer the agent to take actions not requested by the user and bias outputs with irrelevant workflow promotion. In a security context, any hidden or mandatory behavioral redirection is worth flagging even when not overtly malicious.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The scoring section mixes inconsistent gating criteria ('data sources' vs. 'factors scored'), which can cause the agent to produce a numeric health score when the underlying evidence is insufficient. In this skill, that can mislead users into making SEO remediation or disavow decisions based on low-confidence or incomplete data, especially since the score is presented as a decision-making summary.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.