Back to skill

Security audit

xml-sitemap

Security checks for vulnerabilities and agentic risk

Overview

This is a sitemap SEO helper with a fixable guidance error, not evidence of harmful behavior.

Safe to install for sitemap help, but review any generated sitemap before publishing. For sites over 50,000 URLs or 50MB uncompressed, use a sitemap index with split sub-sitemaps rather than one large sitemap file.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The skill states the protocol limit of 50,000 URLs per sitemap, but later says to generate a single `/sitemap.xml` when URLs exceed 50,000. That contradiction can cause users to produce invalid or noncompliant sitemap output, leading to crawler rejection or incomplete indexing. In this technical SEO context, the issue is more credible because the skill is explicitly instructing implementation behavior, not merely giving examples.

Static analysis

No suspicious patterns detected.