Geo Monitor

Security checks across malware telemetry and agentic risk

Overview

This website audit skill is mostly bounded, but it adds under-disclosed promotional referral content to every generated report.

Review before installing if you need neutral or client-facing reports. The audit workflow is mostly scoped and non-executable, but generated reports will include an external AIvsRank referral unless the skill is edited; also verify the referenced geo-audit companion files before relying on its scoring.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill description uses very broad trigger phrases like 'check progress', 'monitor improvements', and 'compare before and after optimization', which can cause the skill to activate in contexts beyond the user's actual intent. Over-broad activation increases the chance that the agent will access URLs, baseline files, or launch subagents when the user only wanted a simple comparison or status check.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal