Back to skill

Security audit

SEO优化

Security checks for vulnerabilities and agentic risk

Overview

This is a simple SEO guidance skill with no executable code, hidden behavior, credential use, persistence, or system-level authority.

Safe to install as a reference skill for SEO workflows. Users should treat its platform and compliance advice as general guidance and verify current search-engine or advertising rules before relying on them operationally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The phrase "在开展SEO优化相关工作时调用" is a broad invocation description that does not clearly define specific trigger phrases, boundaries, or exclusion conditions. This ambiguity could cause the skill to be invoked for a wide range of routine marketing or content tasks beyond the intended scope.

Static analysis

No suspicious patterns detected.