Back to skill

Security audit

SEO 博客写作专业版

Security checks across malware telemetry and agentic risk

Overview

This SEO writing skill is not clearly malicious, but it asks for broad command, file, API, and publishing authority that is not tightly scoped for a writing assistant.

Install only if you are comfortable with a writing skill that may run commands, inspect credential-related environment variable names, read or write files, and integrate with CMS/API/webhook systems. Use it in a restricted workspace, require confirmation before publishing or writing files, and avoid exposing production credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill is presented as an SEO/blog-writing assistant, but the document later expands its scope to generic file, API, and command-execution behavior. This capability mismatch increases the risk of deceptive overreach: users may invoke a seemingly harmless writing skill that can drive broader agent actions than its stated purpose justifies.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs enumerating environment variables matching API, KEY, TOKEN, SECRET, and PROFILE patterns. Even though the example masks values, secret discovery is unnecessary for blog writing and can normalize credential probing, exposing sensitive configuration names and encouraging follow-on exfiltration or misuse.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill claims broad file read/parse/write capability despite being marketed for SEO content generation. Unnecessary write access increases the chance of unintended local data modification, persistence, or abuse through prompt-driven actions unrelated to the user’s writing task.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Advertising generic system command execution from within a blog-writing skill is unjustified and materially increases attack surface. If an agent follows these instructions, user-controlled content or ambiguous prompts could trigger shell actions, enabling host reconnaissance, data access, or further compromise.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation language is broad enough to match ordinary writing or content-creation requests, making accidental activation more likely. When combined with elevated tools like exec, read, grep, and glob, vague triggering increases the risk that high-privilege behavior is invoked in contexts where users expected simple assistance.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The example trigger '请帮我个人博客快速产出' is too generic and does not clearly indicate specialized SEO tooling or privileged actions. Such ambiguity can cause the skill to activate during normal conversation, unexpectedly expanding the agent’s operational scope.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises file-writing capability without a prominent warning that local files may be modified. Users may reasonably treat a writing assistant as content-only, so undisclosed write behavior raises the risk of surprise data changes or overwriting artifacts on the host system.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill describes CMS auto-publishing and webhook/API integrations without clearly warning that content and metadata may be transmitted to external services. This can lead to unintended disclosure of drafts, business data, or internal publishing details, especially in enterprise environments.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.