Back to skill

Security audit

blog-seo-writer-tool-free

Security checks across malware telemetry and agentic risk

Overview

This SEO writing skill is mostly a content helper, but it asks for broad local command capability and gives unclear privacy and credential-handling guidance.

Review this skill before installing. It is not clearly malicious, but users should assume it may run local commands, inspect environment configuration, cache local data, and contact external APIs. Avoid using it in workspaces with sensitive secrets unless the instructions are tightened to name specific required variables, require confirmation before exec/network use, and clarify exactly what data may leave the machine.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill states that FREE edition data is 'all stored locally' and 'not uploaded to the cloud,' but elsewhere it explicitly says some features require network access and external APIs. This creates a misleading trust boundary: users may provide sensitive content or credentials under the false assumption that no remote transmission occurs.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
This is a substantive security documentation inconsistency, not just a wording issue. Claims of local-only handling directly conflict with statements about external API usage, which can cause unsafe operator decisions and accidental exposure of prompts, article drafts, metadata, or API-linked content to third parties.

Context-Inappropriate Capability

Low
Confidence
89% confidence
Finding
The skill includes instructions to enumerate environment variables matching API, KEY, TOKEN, or SECRET, which is not necessary for an SEO writing workflow. Even with masking in the sample output, this encourages secret discovery behavior and normalizes access to sensitive runtime configuration that the skill does not need.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger '请帮我个人博客快速产出' is very broad and does not clearly constrain what actions the agent may take. In a skill that has exec capability, vague invocation language increases the chance that the agent will autonomously choose shell/network actions beyond the user's intended scope.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises itself as a content-writing aid but exposes the exec tool without a clear upfront warning in the description or summary. This obscures the true execution capability of the skill and can cause users to invoke it without realizing it may run shell commands or interact with the local environment.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.