Back to skill

Security audit

geo-optimization-tool

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed GEO marketing helper with a small external API query script and no evidence of hidden local access, persistence, destructive behavior, or credential use.

Install only if you are comfortable with a third-party Tencent Cloud API being contacted for GEO engine data. Do not send confidential drafts, customer data, unreleased strategy, regulated content, or credentials to the listed /check or /suggestions endpoints unless the publisher clearly documents what is transmitted, retained, and accessible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The documented backend capabilities do not align with the stated GEO-monitoring purpose: endpoints such as `POST /check` and `GET /suggestions` suggest content screening or transformation rather than engine-database lookup. This inconsistency is risky because it can conceal actual data flows and cause the skill to send user content to a remote service under misleading pretenses.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
Labeling the backend as a GEO engine database while documenting endpoints for compliance checks and replacement suggestions indicates deceptive or at least materially inaccurate API documentation. That mismatch can hide secondary processing of user prompts or proprietary marketing copy, making it easier to exfiltrate or transform sensitive content without informed user understanding.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.