Back to skill

Security audit

AI SEO Optimizer Pro

Security checks across malware telemetry and agentic risk

Overview

This SEO skill appears to run locally, but it presents mock/random SEO and ranking data as if it were real analysis, so users could rely on misleading results.

Review before installing. Do not treat its keyword volume, ranking, competitor, SERP, or URL-analysis outputs as real unless the publisher replaces or clearly documents the mock/random data sources. Avoid using it for business decisions with proprietary URLs or content until its data sources and privacy behavior are documented.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README advertises features that likely require outbound network access and may transmit URLs, domains, page content, keywords, and ranking data, but it does not disclose that behavior or warn users about data exposure. This is dangerous because users may provide proprietary content or internal URLs under the assumption analysis is local, creating privacy, confidentiality, and compliance risks.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase '给我内容优化建议' is broad and can be invoked in contexts beyond explicit SEO analysis requests, increasing the chance of unintended skill activation. In an agent environment, ambiguous activation boundaries can cause the skill to process user content or URLs when the user did not clearly intend to invoke this capability.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The phrase '生成 SEO 排名报告' is generic enough that normal conversation about reports or rankings could accidentally trigger the skill. Unintended invocation may expose competitive-analysis behavior, consume resources, or cause the agent to act on incomplete or unintended targets.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The command '优化内部链接结构' is overly generic and lacks a required target site or confirmation step, making accidental activation plausible. Because internal-link optimization may imply analysis or recommendations over site structure, vague triggers can lead to unintended execution or confusing agent behavior.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.