Back to skill

Security audit

GEO Prompt Architecture

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only GEO prompt-generation helper with no executable code, hidden persistence, or credential use; its main caveat is a documented Chinese-output default in some reference prompts.

Safe to install for prompt architecture work. Before using it in client workflows, review the language defaults if you need English output, and avoid providing private analytics or internal documents unless you intentionally want the agent to use them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 313)May include surrounding context.

md
- Do not invent product lines, topics, channels, or competitors without labeling the inference.
- Do not assume every prompt should become an article; some should map to category pages, comparison pages, FAQs, reviews, or marketplace listings.
- When the user asks for monitoring prompts, bias toward prompts that can reveal visibility movement over time.
- Do not apply an ecommerce prompt pattern to a marketplace, SaaS, or industrial manufacturer without checking business-model fit first.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Lines L174-L175 require the analysis and output structure to be in Chinese by default, only allowing English for prompt content in a limited case. This enforces a specific language/locale without presenting it as an opt-in or user-selectable option, which matches the language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt hard-requires Chinese for analysis and structure without any user opt-in or documented business justification. This can override user expectations, cause incorrect language output in downstream systems, and create reliability and policy-compliance issues when the user, client, or integrated workflow expects another language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README includes absolute local filesystem paths in example links (e.g. /Users/.../Downloads/...), which unintentionally discloses the maintainer's workstation path structure. While not directly exploitable on its own, it leaks environment details unrelated to the skill's GEO purpose and can aid fingerprinting, social engineering, or reveal sensitive local project organization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The README states that references/final-topic-first-generator-prompt-zh.md provides the operating logic in Chinese, but it does not mention that language selection is optional or user-driven. Because language/locale policy findings apply to natural-language instructions in markdown, this can be read as introducing a fixed alternate-language path without explicit user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.