Back to skill

Security audit

Fulcru

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed marketing workflow for AI-search visibility and does not contain hidden execution, credential access, or destructive behavior.

Installers should treat this as a marketing and content-strategy aid. Review any generated competitive claims before publishing, because the skill intentionally asks the agent to compare brands and draft public-facing content, but it does not request unusual local access or credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description contains very broad trigger phrases such as 'use when someone asks why ChatGPT/Gemini/Perplexity recommend competitors,' 'asks about AEO, GEO, answer engine optimization, LLM SEO, or AI search visibility,' and related content-writing requests. This can cause the agent to invoke the skill for a wide range of loosely related marketing, SEO, branding, or competitive-analysis queries, increasing the chance of inappropriate activation and untrusted web-driven behavior outside the user's actual intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.