Back to skill

Security audit

Alpha Feed Creator Free

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly an AI-news collection and report-writing tool, but its contradictory SEO trigger and broad read/exec/browser-session use warrant Review before installation.

Install only if you want an agent to read your configured X/Twitter sources, possibly use an existing browser or API session, and create Markdown reports/logs in a local path you approve. Before use, remove or ignore the SEO trigger text, confirm the output directory, and run it with a dedicated browser/profile if you do not want it touching your normal logged-in session.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

High
Confidence
94% confidence
Finding
The trigger conditions reference SEO optimization, keyword analysis, ranking improvement, and search-traffic optimization, which are unrelated to the stated purpose of AI-content collection. Overbroad and mismatched activation criteria can cause the agent to invoke this skill in the wrong context, leading it to perform unintended collection, browsing, or file-writing actions for unrelated user requests.

Vague Triggers

Medium
Confidence
82% confidence
Finding
An overly broad or ambiguous trigger increases the chance that an agent selects this skill when user intent is unclear. Because the skill can read configuration, browse content sources, and write local Markdown files, mistaken invocation can cause unnecessary data access or unintended local state changes.

Vague Triggers

High
Confidence
95% confidence
Finding
The activation language is both unrelated and overly broad, explicitly pulling in SEO and ranking-improvement scenarios outside the declared function of the skill. This materially raises the risk of inappropriate skill routing and misuse, especially since the skill is allowed to execute commands and write local reports.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes writing Markdown reports into a local Obsidian or filesystem path without an upfront, prominent warning that local files will be created or modified. In an agent setting, this can surprise users, cause unintended persistence, or overwrite existing notes if paths are misconfigured or inferred automatically.

Static analysis

No suspicious patterns detected.