mar-competitor-analysis

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only competitor SEO analysis skill with disclosed API-key and optional SEO-tool data access, and no evidence of hidden code, destructive actions, or persistence.

Install only if you are comfortable giving this skill access to the SKILLBOSS key and any connected SEO, analytics, Search Console, or AI-monitoring data needed for competitor analysis. Prefer least-privilege credentials and avoid connecting unrelated business data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The description includes broad trigger phrases such as "who ranks for" and "competitive analysis," which can match ordinary SEO or marketing questions outside the intended scope. This can cause the skill to activate unexpectedly, increasing the chance that unrelated user requests are routed into competitor-analysis workflows and produce irrelevant or over-privileged behavior.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger list contains multiple ambiguous phrases including "analyze competitors," "competitive analysis," and "what are they doing differently," without contextual qualifiers. In a skill-routing system, these broad phrases may overlap with many normal business or content requests, causing unintended invocation and misapplication of the skill's instructions or connected data sources.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal