Back to skill

Security audit

Ai Seo

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only AI search optimization guide with disclosed, purpose-aligned advice and no hidden execution or data exfiltration behavior.

Install only if you want AI-search and AI-citation optimization advice. Review any recommendations before applying them to public site files, especially robots.txt, pricing.md, and llms.txt, because those choices can affect crawler access and public business information.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill’s invocation description is very broad and contains many loosely defined trigger phrases such as 'optimize for ChatGPT' and 'how do I show up in AI answers.' This can cause the agent to invoke the skill for ambiguous marketing, content, or product questions where a narrower skill would be more appropriate, increasing the chance of misrouting, unintended file reads, and inappropriate advice in unrelated contexts.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The eval explicitly rewards the skill for triggering on vague, casual phrasing ('we noticed our competitors are showing up... what do we need to change?') without strong scope boundaries. This can cause overbroad activation of the ai-seo skill in situations that may actually require other skills or more precise routing, leading to confused task handling, inappropriate advice, or bypass of more specialized workflows.

Static analysis

No suspicious patterns detected.