Back to skill

Security audit

SEO (Site Audit + Content Writer + Competitor Analysis)

Security checks across malware telemetry and agentic risk

Overview

This SEO skill is documentation-only and its local preference/history storage is disclosed and aligned with its SEO workflow.

Before installing, know that this skill keeps SEO preferences, audit history, keyword tracking, and related site context in ~/Clawic/data/seo/. That is useful for continuity, but it may contain business-sensitive information, so review or delete that folder if needed and set target_market correctly for non-US sites.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to persist user preferences and contextual history to local files without any notice, consent flow, retention limit, or data-minimization guidance. Even though the data is SEO-related, it can include business-sensitive information such as site profiles, audit history, rejected recommendations, and team constraints, creating a privacy and confidentiality risk if stored automatically.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
Hard-coding `target_market: en-US` as a default can silently steer recommendations, content strategy, and SEO decisions toward the wrong geography or language when the user has not provided that preference. In an SEO skill, this context matters operationally because it can cause misleading advice, incorrect keyword targeting, and poor optimization outcomes for non-US/non-English sites.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.