SEO Afiliate guide

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Spanish affiliate-writing skill, but it encourages generated reviews to imply firsthand product testing that may not have happened.

Install only if you will review outputs before publishing. Replace any implied firsthand testing with verified, user-supplied, or sourced claims, and make affiliate disclosures, prices, ratings, and availability truthful and current.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill explicitly tells the model to write as if it had personally tested products, using phrases like having tried a product for weeks. That is deceptive content generation: it fabricates first-hand experience to increase trust, which can mislead users into making purchase decisions based on false evidence and may create legal, platform-policy, and consumer-protection risk.

Vague Triggers

High
Confidence
93% confidence
Finding
The activation description is extremely broad and says to use the skill whenever the user wants to write or improve buying guides, comparisons, reviews, affiliate posts, or similar phrases. Overbroad triggers can cause the skill to activate in ordinary product discussions or generic writing tasks, overriding user intent and injecting affiliate-oriented persuasive behavior where it was not requested.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill metadata and description mandate Spanish output without checking the user's preferred language. This can cause unintended language switching, degrade usability, and lead the assistant to ignore explicit or implicit user language context; while not a direct security flaw, it is a behavioral policy weakness that can produce incorrect or intrusive activations.

Ssd 4

Medium
Confidence
97% confidence
Finding
The skill instructs the model to fabricate product testing experience specifically to build E-E-A-T trust signals. In the context of affiliate marketing, this is more dangerous because the deception is tied to commercial persuasion and can manipulate consumers with false claims of hands-on evaluation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal