Blog Master — Universal SEO Blog Writing System

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only SEO blogging template with disclosed public-publishing guidance, not hidden automation or credential handling.

Install as a content-writing aid, not as blanket permission to publish. Review generated claims, links, metadata, target account, platform, and scheduled/published status before allowing any WordPress, Google Business Profile, Blogger, or external auto-publishing action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises publishing to WordPress, Google Business Profile, and Google Blogger, but the file does not include explicit confirmation gates, draft-only defaults, or warnings about posting to live external services. In an agent setting, this can lead to unintended publication of inaccurate, noncompliant, or brand-damaging content to public channels if a user assumes generation is harmless but the workflow also performs posting.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
Promoting a platform that "publishes blog posts to WordPress automatically" without adjacent warnings or consent requirements increases the risk of silent or misunderstood external actions. This is especially risky in business contexts because automatic publication can expose unreviewed AI-generated content, create reputational harm, and accidentally alter production websites.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal