Back to skill

Security audit

Seo Blog Writer

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly an SEO prompt sheet plus an off-platform paid upsell, while advertising bundled workflows and scripts that are not present.

Treat this as a Review item before installing. The inspected package does not include the advertised scripts or full workflow, and payment/delivery is pushed through Telegram, PayPal, or crypto outside the reviewed skill package. Avoid relying on the advertised Pro contents unless you independently trust the publisher and delivery path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The manifest and description claim substantive functionality including Python scripts and a bulk SEO workflow, but the file content is only promotional text and upgrade instructions. This is dangerous because users or agents may rely on nonexistent local capabilities, leading them to trust deceptive packaging and potentially follow external payment or delivery paths outside the expected skill boundary.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill is presented as a usable SEO tool, but the body is primarily an advertisement directing users to external payment channels, Telegram, PayPal, and crypto. This is dangerous because it turns the skill into a monetization and off-platform redirection mechanism, which can facilitate phishing, fraud, or policy evasion under the guise of a legitimate agent capability.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The markdown tells users to 'Ask your AI agent' followed by generic content-creation requests like 'Create an outline' and 'Write an SEO-optimized product description' without defining any explicit activation phrase, scope limitation, or exclusion conditions. These requests overlap with common everyday prompts and could cause unintended invocation because the file does not specify when this skill should activate versus when general writing behavior should apply.

Static analysis

No suspicious patterns detected.