Back to skill

Security audit

seo-audit

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed SEO audit guidance skill with no executable code, persistence, or hidden high-impact behavior.

Before installing, be aware this skill may activate for broad SEO help requests and may read a local product marketing context file if one exists. Only provide Search Console, analytics, or site access when you intend the agent to use it for the audit.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger description is unusually broad and includes vague phrases like 'help with SEO' and 'my SEO is bad,' which can cause this skill to activate for generic requests that may be better handled by other, narrower skills. Over-broad routing can misclassify user intent, leading to inappropriate data access or actions within the wrong workflow, especially in agent systems where skills may read project files or steer subsequent tool usage.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The eval explicitly rewards triggering the SEO audit skill on vague phrasing like 'why am I not ranking,' which broadens activation beyond clear user intent. Overly broad triggers can cause the wrong skill to run, leading to irrelevant guidance, missed routing to more appropriate skills, and increased exposure to downstream tool use or assumptions without sufficient context.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.