Back to skill

Security audit

GEO

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only marketing guidance skill for improving brand visibility in AI recommendations, with no code execution, credential access, persistence, or hidden data handling.

Before installing, consider whether you want a marketing skill that may activate on broad AI visibility or recommendation discussions. Its advice includes public-platform and multi-model audit tactics, so users should apply platform rules and avoid spam or deceptive promotion.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list is broad and includes generic marketing/AI terms such as 'AI optimization' and 'AI recommendations' without clear scope boundaries. This can cause the skill to activate in unrelated conversations, leading to unintended guidance, prompt hijacking of user workflows, or inappropriate application of brand-promotion tactics outside the intended GEO context.

Static analysis

No suspicious patterns detected.