Back to skill

Security audit

blog-seo-writer

Security checks across malware telemetry and agentic risk

Overview

The skill is not plainly malicious, but it presents an SEO-writing purpose while declaring broad command, file, and API capabilities with inconsistent audit-style examples.

Review this skill carefully before installing. It may be intended as a generated SEO helper, but its documentation asks for more authority than an SEO writer normally needs and does not clearly explain what commands, files, APIs, or API keys it would use. Install only if you are comfortable restricting it to explicit user-provided content and denying command execution unless a specific action is justified.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The skill is presented as an SEO blog writer, but the documentation also advertises generic file processing, API integration, command execution, and information retrieval. That scope mismatch is dangerous because it can cause an agent or user to grant far broader privileges than expected, creating an opportunity for unintended data access, shell execution, or network actions under a benign-seeming label.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Declaring command execution for a blog SEO writer is a high-risk overreach because shell access can be used to inspect files, modify the environment, or run arbitrary system commands unrelated to content generation. In this context, the mismatch makes the capability especially suspicious and increases the chance of misuse or privilege abuse by an agent invoking the skill automatically.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
Generic file read/write capabilities are broader than necessary for an SEO-writing skill and can expose local data or enable unintended file modification. Even without explicit malicious instructions, this creates a risk of overwriting documents, reading sensitive project files, or persisting unexpected outputs in the user's workspace.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
Broad API integration and information retrieval claims expand the skill from content generation into general external communication and data gathering. That increases the attack surface for exfiltration, unreviewed outbound requests, or agent behavior that fetches or transmits data beyond the user's expectation for an SEO-writing tool.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The request/output schema describes a grading or audit tool with scores, pass/warn statuses, and compliance-style results, which directly contradicts the stated SEO blog-writing purpose. This kind of deceptive or inconsistent interface can hide the real function of the skill, making it easier to smuggle unrelated behavior past review and harder for users to understand what the agent will actually do.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The examples reinforce the inconsistency by showing strictness checks, grades, and compliance evaluations instead of SEO content generation. In security review, such contradictions are dangerous because they suggest copy-pasted or disguised functionality, reducing trust in the declared purpose and increasing the risk that hidden behaviors accompany the skill.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
A skill that can read, write, execute commands, and access external APIs should clearly warn users about those actions. Omitting explicit warnings undermines informed consent and makes it more likely that users or orchestrators will invoke the skill without understanding its potential to modify files, run commands, or send data externally.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.