Back to skill

Security audit

Serpzilla SEO Guest Posting Skill for OpenClaw

Security checks across malware telemetry and agentic risk

Overview

This skill openly helps users operate Serpzilla for paid SEO placements and includes confirmation steps before purchases or financially significant placement actions.

Install only if you intend to let an agent operate your Serpzilla advertiser account. Use a scoped or low-balance account where possible, review donor site prices and remaining balance before confirming purchases, and remember that the local mcporter setup may store your Serpzilla credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README explicitly presents workflows to purchase guest posts, link insertions, and manage placements through an external platform, but it does not warn that the skill can trigger paid actions or modify an external Serpzilla account. In an agent setting, missing consent and risk disclosure increases the chance of unintended spending, unauthorized campaign changes, or abuse of connected accounts.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal