Back to skill

Security audit

Seo Keyword Research

Security checks across malware telemetry and agentic risk

Overview

This SEO research skill uses disclosed website crawling and AIsa/DataForSEO API calls for its stated purpose, with only a scoping caution around broad invocation wording.

Install only if you are comfortable sending target URLs, crawled page excerpts, keyword inputs, competitor names, and SEO strategy context to AIsa/DataForSEO. Keep AISA_API_KEY private, avoid confidential internal sites unless approved, and invoke this for SEO keyword research rather than generic web research.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The README instructs the agent to use the skill for broad categories like web search, research, source discovery, and content extraction, which overlap with many generic user requests and can cause the skill to be invoked outside its narrowly intended SEO scope. In an agent environment, overly broad invocation guidance increases the chance of unnecessary website crawling, external API use, and data handling in contexts where the user did not specifically request SEO analysis.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The invocation description is broad enough to match general web research, source discovery, and content extraction requests, which can cause the skill to trigger outside narrow SEO-keyword tasks. Overbroad activation is dangerous because this skill performs crawling and third-party API transmission, so accidental invocation can send user-provided URLs or extracted site content to external services without clear user intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.