Back to skill

Security audit

品牌GEO分析

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches its brand-analysis purpose, but its generated report can materially overstate positive sentiment and hide negative feedback in key summary areas.

Review before installing. Do not use confidential, regulated, or unreleased business information unless you are comfortable sending the submitted prompts and brand/competitor data through the RedFoxHub-backed external AI search services. Treat generated sentiment summaries cautiously until the positive-rate calculations are fixed; check the raw sentiment distribution and source answers rather than relying only on the report headline.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill instructs the agent to use environment variables, read and write local files, and make network requests, but it does not declare permissions or boundaries for those capabilities. This creates an authorization gap where a user or runtime may not clearly understand that external data exfiltration and local file modifications will occur.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The summary string hard-codes '正面率 100%(无负面评价)' instead of deriving it from the actual sentiment counts. In a GEO/brand-analysis skill, this can materially mislead users about reputation and decision-making, producing falsified reports that appear data-driven while concealing negative sentiment.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The fingerprint section labels '正面率' as 100 minus the negative percentage, which treats neutral sentiment as positive and conflicts with the report's own three-class sentiment model. This misstates sentiment quality and can systematically inflate perceived brand performance, especially when neutral responses dominate.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The competitor comparison uses '正面率=1-负面率', again collapsing neutral into positive and distorting comparative results. In a competitive brand-analysis context, this can bias side-by-side comparisons and lead users to wrong conclusions about both the target brand and competitors.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README states that user-provided brand names, categories, and generated questions are automatically sent to Doubao, Kimi, and DeepSeek, but it does not prominently disclose the third-party data transfer, retention, or privacy implications. Users may unknowingly submit sensitive business plans, campaign strategy, customer data, or confidential brand-monitoring queries to external services, creating a real confidentiality and compliance risk.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list includes broad terms such as 'GEO' and generic SEO/visibility phrases that can overlap with ordinary conversation, causing the skill to activate unexpectedly. Overbroad activation is risky here because the skill performs external queries, accesses credentials, and writes files, so accidental invocation can leak user-provided brand or query data to third-party services.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill asks users to obtain and configure an API key in a file or environment variable without providing clear handling and disclosure guidance. This can lead users to expose secrets in chat, logs, shared config, or improperly scoped environments, increasing the chance of credential leakage and unauthorized API use.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill states it will query multiple external AI platforms but does not clearly warn users that brand names, competitor lists, and generated questions will be transmitted to third parties. This is dangerous because business-sensitive research inputs may be disclosed outside the local environment without informed consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.