Seo Ladders

Security checks across malware telemetry and agentic risk

Overview

This is a coherent SEO automation MCP skill that discloses its API-key requirement, external service use, content generation, CMS publishing, and local export capabilities.

Install only if you are comfortable sending website, keyword, ranking, and generated article data to SEO Ladders. Use a revocable or scoped API key where possible, test with non-production CMS/webhook credentials first, and require explicit review before publishing or saving generated content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill advertises broad natural-language prompts such as "Audit my website" and "Publish my latest article," which can encourage an agent to invoke powerful tools based on loosely phrased user requests without explicit confirmation. In a skill that can publish content, write locally, and interact with external sites, ambiguous trigger phrases increase the chance of unintended side effects from over-eager tool use.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The description emphasizes automation and direct publishing but does not warn users that the skill can perform side-effecting actions such as publishing to WordPress/webhooks and saving content to disk. This omission can mislead users and agents about the trust boundary, increasing the risk of accidental writes or publication in environments where the skill is assumed to be informational only.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal