Back to skill

Security audit

seo-content-brief

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent SEO briefing helper that may browse supplied sites and competitor pages, with no evidence of hidden execution, persistence, destructive behavior, or credential theft.

Installers should be comfortable with the skill using web research on supplied URLs and competitor pages. Avoid providing private staging URLs, confidential pages, or sensitive business material unless the connected browsing and SEO tools are approved for that data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
97% confidence
Finding
The invocation description includes broad phrases such as "write a brief," "brief for," "content plan," and "outline for," which can easily appear in ordinary conversation outside the intended SEO-content-brief context. The file does not provide exclusion conditions or negative examples to narrow when the skill should or should not activate.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The markdown describes retrieving existing page content, homepages, sitemaps, and SERP competitor pages as part of the process, which implies outbound network access and processing of user-provided URLs. There is no user-facing warning about web requests, third-party data access, or the privacy implications of analyzing supplied sites and competitors.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.