SEO Audit Bot

Security checks across malware telemetry and agentic risk

Overview

This is a coherent SEO audit skill that fetches user-specified websites and reports SEO issues, with no evidence of hidden data access or harmful behavior.

Install this if you want an agent to audit public or authorized websites for SEO. Be aware it may fetch pages, robots.txt, and sitemap.xml for supplied URLs; do not use it on private internal sites unless that is intended. If running the shell helper, expect curl network requests and temporary /tmp/seo_* files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description uses very broad trigger phrases like 'audit, analyze, or check the SEO of a website' and 'compare SEO between two sites,' which can match many ordinary user requests and cause over-invocation. Ambiguous invocation scope is dangerous because it may route unrelated browsing or analysis tasks into this skill, increasing unintended external fetching and expanding the attack surface for prompt injection from arbitrary websites.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal