Back to skill

Security audit

seo-schema

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed SEO structured-data helper with only low-impact concerns around broad activation terms and possible output file creation.

Installers should understand that this skill helps an agent inspect web pages or provided HTML for SEO schema and may generate report or JSON files in the workspace. Use it when you intend structured-data work, and review generated markup before publishing it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are very broad and include generic terms like 'schema', 'markup', and 'structured data', which can cause the skill to activate in unrelated contexts. Unintended invocation can lead the agent to read files, inspect URLs, or generate outputs when the user did not clearly request this capability, increasing the chance of oversharing, unnecessary tool use, or workflow hijacking.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The skill states it produces output files like SCHEMA-REPORT.md and generated-schema.json without explicitly warning that files may be created or overwritten. In agent environments with workspace write access, this can cause unexpected file creation, accidental overwrite of existing artifacts, or disclosure of analyzed content into persistent files the user did not intend to store.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.