serp-features

Security checks across malware telemetry and agentic risk

Overview

This is a single-file SEO reference skill for SERP feature analysis and does not request credentials, install code, file access, persistence, or privileged actions.

Safe to install as an informational SEO helper. Review any related skills it recommends before allowing live site changes, CMS access, schema deployment, or publishing workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation guidance is broad enough to trigger on many generic SEO/search-related terms, which can cause the agent to select this skill when a more specific or safer skill would be a better fit. Over-broad routing is a real security and reliability issue because it expands the skill’s activation surface, increasing the chance of prompt/context hijacking, mis-scoping, or unintended disclosure through the wrong skill path.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal