Back to skill

Security audit

Geo Rank Architect

Security checks across malware telemetry and agentic risk

Overview

This skill is mainly a GEO/SEO content optimizer, but it asks for command execution and describes broad file, API, and command abilities without tight limits.

Review this skill before installing. It appears to be a content optimization helper rather than malware, but only enable it in an environment where broad command execution is acceptable, and require explicit approval before it reads or writes files, invokes commands, or uses external APIs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill’s stated purpose is GEO/SEO optimization, but the documentation later expands its scope to generic file handling, API use, command execution, and information retrieval. This capability mismatch increases the chance that an agent will grant or use powerful operations unrelated to the user’s intent, enabling overprivileged behavior and accidental misuse.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill claims to be 'pure LLM-driven' while also requiring exec support and describing file read/write and command invocation behavior. This inconsistency can mislead reviewers and users about the actual privilege level of the skill, causing it to be trusted or enabled under false assumptions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Overly broad trigger conditions make the skill likely to activate for generic SEO-related requests, even when the user did not intend to invoke a tool with exec-capable or file-modifying behavior. Over-triggering increases the attack surface for prompt steering, unintended tool use, and application in contexts outside its safe design scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The listed trigger keywords are broad, high-frequency SEO terms that can cause accidental or opportunistic activation in unrelated conversations. In a skill that advertises operational capabilities beyond plain text transformation, this increases the likelihood of unintended execution paths being exposed.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation references file writes, API integration, and command execution without giving clear user-facing warnings about the associated risks, scope, or consent requirements. Users and agents may therefore enable a skill with side-effecting capabilities without understanding that it can modify files, call external services, or run commands.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.