Back to skill

Security audit

conqueror-seo-project-setup

Security checks across malware telemetry and agentic risk

Overview

This is a coherent SEO setup skill that asks for expected project context and Search Console data, with local persistence disclosed and user-directed.

Before installing, expect this skill to organize SEO work in a local folder and to ask for business strategy materials and Search Console data. Use a project folder you control, avoid sharing credentials or unnecessary confidential material, and redact sensitive customer or internal details where possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly encourages creating a persistent local SEO workspace to store notes, exports, preferences, and project context over time, which can include sensitive business and operational data. While persistence is core to the workflow, the skill does not instruct the agent to obtain explicit consent, minimize collected data, or warn users about local retention and confidentiality risks.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill asks users to share customer interviews, positioning docs, pitch decks, landing pages, and strategy memos, all of which may contain confidential business information or personal data. In context this supports SEO strategy intake, but the absence of confidentiality guidance, least-privilege collection limits, or redaction instructions creates unnecessary exposure risk.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs users to connect Google Search Console and pull live performance data, which exposes site telemetry such as queries, pages, countries, and devices. This is a legitimate SEO data source, but the skill fails to warn that the agent will access potentially sensitive business intelligence and does not describe consent boundaries or data handling expectations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.