Back to skill

Security audit

Geo Metrics Tracker

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent planning aid for GEO metrics monitoring, with no evidence of hidden execution, credential use, persistence, or destructive behavior.

Before installing, understand that this is mainly a planning and template skill, not a live monitoring service. If you use its suggested data sources such as logs, analytics, or AI answer samples, scope them carefully and avoid unnecessary sensitive or personal data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises an operational monitoring and alerting skill for ongoing GEO metric tracking over time, including dashboards, anomaly detection, and reaction workflows. The supplied code does not implement any of those behaviors. Instead, it only defines a few default metric definitions, renders them as a markdown table, builds an example schema table, and outputs the result to stdout or a file. This is related to GEO metrics conceptually, but its primary purpose is static schema/catalog generation, not real-time monitoring orchestration. Therefore the description materially overstates and misrepresents the code’s actual functionality.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger guidance explicitly says not to limit invocation to exact keywords and to trigger on loosely inferred intent, which can cause the skill to activate in contexts broader than the user intended. Over-broad auto-invocation can route sensitive or unrelated requests into a workflow that encourages data-model design, collection planning, and automation guidance, increasing the chance of inappropriate handling, unnecessary data exposure, or confused-deputy behavior in multi-skill systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.