Back to skill

Security audit

seo-ecommerce

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed e-commerce SEO helper that fetches product pages and optionally uses paid marketplace data, with no hidden persistence or destructive behavior found.

Install only if you want an agent to fetch product/store URLs and optionally use DataForSEO paid marketplace APIs. Treat UCP endpoint probing as an active network check and run it only for sites you are authorized to assess.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill materially expands from SEO analysis into agentic-commerce/UCP auditing and endpoint probing, which introduces behavior outside the declared purpose. This scope creep is dangerous because users invoking an SEO skill may unknowingly trigger capability discovery and network probing against merchant-declared endpoints, increasing the chance of unintended external interaction and misuse.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Endpoint reachability probing is not necessary for e-commerce SEO analysis and creates an active network interaction against arbitrary declared capability URLs. Even with some SSRF blocking in tooling, this broadens the attack surface by enabling external probing of attacker-controlled endpoints under the cover of a benign SEO workflow.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad enough to match common product and SEO discussions, which can cause the skill to activate in contexts the user did not intend. Overbroad invocation is risky here because the skill can fetch external pages and optionally invoke paid third-party APIs, amplifying the effect of accidental activation.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The workflow instructs the agent to fetch and parse arbitrary product pages without clearly warning the user that external network access will occur. This is dangerous because users may disclose internal, staging, or sensitive URLs expecting local analysis, while the skill silently performs outbound requests to those targets.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.