article-page-generator

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only SEO article-page helper whose main caution is that audits use project context and web research by default.

Use this normally for public or non-sensitive article SEO work. For confidential drafts, unreleased product names, customer references, or private strategy, tell the agent to skip search or provide sanitized keywords and competitor URLs yourself.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill directs the agent to proactively perform web searches and fetch competitor articles by default, but it does not require user consent or a warning that article-derived terms, product names, or internal context may be sent to external services. This creates a real privacy and data-governance risk, especially when the analyzed article or project context contains unpublished strategy, customer references, or sensitive brand information.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This section makes external search part of the default analysis workflow and instructs the agent to output search results, yet it never addresses the privacy implications of deriving queries from user-provided article text. If the article includes confidential launch plans, internal product terminology, or embargoed topics, those details could be exposed through third-party search providers and competitor page retrieval.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal