Back to skill

Security audit

programmatic-seo

Security checks across malware telemetry and agentic risk

Overview

This skill provides scoped guidance for creating programmatic SEO pages and does not request unusual access or perform hidden actions.

Before installing, users should be comfortable with the skill reading local product-marketing context files when present. Otherwise, its behavior is limited to strategy and content-planning guidance for scaled SEO pages.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The eval explicitly rewards triggering on vague, casual phrasing for programmatic SEO requests without defining tighter boundaries for when the skill should or should not activate. Overly broad activation criteria can cause misrouting of unrelated user requests into this skill, producing incorrect guidance and making downstream security or policy controls easier to bypass through ambiguous wording.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.