Back to skill

Security audit

Cb Seo Sem Strategy

Security checks for vulnerabilities and agentic risk

Overview

This is a descriptive international SEO/SEM planning skill with no code execution, API access, persistence, or hidden data-handling behavior.

Safe to install for strategic SEO/SEM planning. Users should verify current search-engine policies, ad-platform rules, privacy requirements, and local market data before acting on recommendations, and should avoid treating example budgets, CPCs, or regional platform shares as current facts without checking live sources.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The getting-started trigger is broad enough to activate on many generic international search or marketing requests, which can cause the skill to inappropriately take over conversations outside a clearly scoped user intent. This is primarily a scope-control and routing issue rather than code execution, but it can lead to misfiring behavior, unintended data sharing into the skill context, or user confusion when the agent selects this skill too aggressively.

Natural-Language Policy Violations

Low
Confidence
72% confidence
Finding
Including a Chinese-language scenario without documented language-selection rules can cause the agent to respond in an unexpected language or infer language preference from example content rather than explicit user choice. In multi-skill or automated environments, that can create usability failures, miscommunication, or accidental disclosure in the wrong language, though the security impact is limited.

Static analysis

No suspicious patterns detected.