SEO Autopilot Pro

Security checks across malware telemetry and agentic risk

Overview

This skill openly automates SEO publishing, but it can change a website repository and push to production without a clear human approval step.

Install only if you intentionally want an agent to modify and publish your website repository. Before enabling it, use a staging branch or pull requests instead of direct pushes to main, review generated diffs and content before deployment, restrict report sources to trusted inputs, limit the git credential or bot account it can use, and document how to disable the hook and undo changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill is explicitly designed to generate code, commit changes, push to git, and trigger production deployment with no explicit user approval gate or impact warning. Because it also ingests externally generated reports and runs automatically via hooks, this creates a high-risk path for unintended or malicious content to be transformed into live production changes.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal