competitor-research

Security checks across malware telemetry and agentic risk

Overview

This instruction-only SEO competitor research skill is coherent and purpose-aligned, with no evidence of hidden code, persistence, credential use, destructive actions, or deceptive behavior.

Safe to consider installing for SEO competitor research. Be mindful that web searches/fetches can expose keywords or competitor domains to external providers, and review any local project context before relying on or sharing generated reports.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI07: Insecure Inter-Agent Communication
Info
What this means

Search terms, competitor domains, or target keywords may be shared with the web/search provider used by the agent.

Why it was flagged

The skill may send search queries or URLs to external web/search/fetch providers. This is disclosed and aligned with competitor research.

Skill content
Use mcp_web_fetch or WebSearch to fetch 2–3 top-ranking pages
Recommendation

Avoid using sensitive unreleased product names or confidential strategy terms in searches unless you are comfortable sending them to the configured web/search provider.

#
ASI06: Memory and Context Poisoning
Low
What this means

Internal business context in project-context.md may be used in generated competitor reports, and inaccurate or untrusted content in that file could affect recommendations.

Why it was flagged

The skill can incorporate a local project context file into competitor reports. This is purpose-aligned but means persistent project context may influence outputs.

Skill content
read `project-context.md` if present
Recommendation

Keep project-context.md accurate and free of untrusted instructions, and review generated reports before sharing them externally.