Back to skill

Security audit

GEO搜索占位架构师

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be an SEO/GEO content helper, but it asks for broad command execution and advises administrator execution without clear limits.

Review before installing. Use this only in a restricted workspace with non-admin privileges, and require explicit approval before any command execution, file write, or external API submission. Do not provide sensitive documents or credentials unless you are comfortable sending their content through the configured LLM/API path.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:17
Finding

Unnecessary Command Execution Capability and Privilege-Elevation Guidance

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17-19; supporting instructions at lines 225, 240, 243-244, 341-342, 385, and 407
Vulnerability Type: Excessive tool permissions and unsafe privilege-elevation guidance
Risk Level: Medium

Evidence

The Skill declares unrestricted command execution despite describing a workflow that primarily transforms supplied text:

yaml
tools:
- read
- exec

Supporting instructions state that the Skill requires command-line execution for file reading, file writing, and command invocation. The troubleshooting guidance at lines 385 and 407 also recommends running with administrator privileges when file permissions are insufficient.

Technical Analysis

The documented core functions—content scoring, FAQ generation, summary generation, and JSON-LD construction—do not inherently require arbitrary operating-system command execution. Nevertheless, the Skill requests the broad exec capability without defining:

  • An allowlist of permitted commands
  • Argument or input validation
  • Filesystem path restrictions
  • A mandatory non-privileged sandbox
  • User confirmation before command execution
  • A concrete implementation that justifies command access

This violates the principle of least privilege. If untrusted article content, filenames, command parameters, or later instructions influence an agent's tool use, the broad capability could expose the host to arbitrary commands under the agent's operating-system identity.

The recommendation to run as an administrator compounds this risk. It encourages expanding privileges instead of correcting file ownership, narrowing the required paths, or using a dedicated workspace. The document does not itself execute commands or contain a malicious payload, so exploitation depends on an agent translating these broad instructions into unsafe tool calls.

Attack Path

  1. A user or external source supplies attacker-contr ...[truncated 1591 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove exec from the declared tools because the documented content-transformation workflow can be performed through text processing.
  2. Retain read only if local document access is essential, and restrict it to an explicit project workspace.
  3. Remove all recommendations to run the agent as an administrator. Resolve permission errors through correct ownership, narrowly scoped access controls, or a dedicated non-privileged workspace.
  4. If command execution is genuinely required, document every permitted executable and fixed argument pattern rather than authorizing generic shell commands.
  5. Invoke executables directly without a shell, and never concatenate user-controlled content, filenames, titles, or paths into command strings.
  6. Canonicalize and validate paths before access; reject absolute paths, traversal sequences, symbolic-link escapes, and paths outside the designated workspace.
  7. Require explicit user approval for each command, file write, external request, or operation outside the content-processing workflow.
  8. Run commands in a non-privileged sandbox with minimal filesystem mounts, restricted environment variables, network access disabled by default, resource limits, and execution timeouts.
  9. Prevent child processes from inheriting API keys or unrelated credentials. Pass only the minimum environment variables needed for a specific operation.
  10. Add security tests covering shell metacharacters, malicious filenames, path traversal, symbolic links, permission failures, and attempts to access files outside the workspace.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest uses very broad activation language spanning SEO, keyword analysis, ranking improvement, AI model usage, agent orchestration, and LLM applications. Over-broad routing phrases increase the chance that the skill is auto-selected for unrelated requests, which becomes riskier because the skill also declares privileged capabilities like exec.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill’s stated purpose is GEO/SEO content optimization, but the documentation also advertises generic exec and file-processing capabilities that are not narrowly scoped to that purpose. In an agent environment, broad command execution materially expands the attack surface because normal SEO-style prompts could be escalated into filesystem or shell actions without clear functional necessity or constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown describes API use, file handling, and command execution, but does not provide clear user-facing warnings about what data may be sent externally, what files may be read or written, or what system impact commands could have. This omission weakens informed consent and increases the likelihood of privacy, integrity, or operational harm when the skill is invoked in automated flows.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document claims the skill is 'pure LLM-driven' while nearby sections state that it can perform command execution and file read/write. This contradiction can mislead users and higher-level agent policy into underestimating operational risk, making unsafe tool invocation more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger keyword list contains broad, collision-prone terms such as AI搜索优化, JSON-LD, FAQ Schema, and related generic SEO/AI phrases without contextual constraints. In agent ecosystems, this can cause over-invocation of a skill that may then access APIs, files, or exec-capable tooling in situations the user did not intend.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.