Back to skill

Security audit

Local Falcon

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Local Falcon SEO guidance skill with optional account-connected MCP workflows, with no evidence of hidden execution, exfiltration, or destructive behavior.

Safe to install as an instruction-only SEO skill. Before connecting the optional MCP server, review the separate @local-falcon/mcp package, protect the API key, and require confirmation before reading account data, running scans that consume credits, enabling AI Analysis, creating campaigns, or changing Falcon Guard monitoring.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The skill is configured for auto-invocation and includes many broad triggers such as 'local SEO,' 'local search,' 'Google Business Profile,' and 'AI visibility,' which can match ordinary user conversations far beyond explicit requests for this skill. Over-broad activation can cause unintended routing, unnecessary tool-oriented guidance, and increased exposure to the skill's embedded instructions, making prompt-scope hijacking and user-confusion more likely even without direct code execution.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains several broad, common phrases such as "local seo," "google business profile," and "map pack" that could cause the skill to activate in many ordinary conversations beyond explicit intent to use this specific skill. This creates an overbroad invocation surface, which can lead to unintended routing, prompt/context hijacking opportunities, or the skill influencing responses when the user did not clearly request it.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation instructs use of account-scoped MCP/API operations and describes authenticated access to external services, but it does not clearly warn that business/account data will be transmitted to Local Falcon or that some actions may consume credits. In an agent setting, this can lead users to unknowingly authorize external data transfer or billable actions, especially because the workflows encourage automatic tool use and even 'ALWAYS' enable certain options.

Session Persistence

Medium
Category
Rogue Agent
Content
**Step 2: Get a Local Falcon API key**
- Go to [localfalcon.com/api/credentials](https://www.localfalcon.com/api/credentials/)
- Create or copy your API key
- Requires an active Local Falcon subscription

**Step 3: Configure Claude Code**
Confidence
88% confidence
Finding
Create or copy your API key - Requires an active Local Falcon subscription **Step 3: Configure Claude Code** Add to your Claude Code MCP settings (usually `~/.config

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
90% confidence
Finding
The trigger phrase 'review velocity' contains the common command term 'review' and can collide with built-in or other skill-routing behaviors, creating shadow-command ambiguity. In an auto-invocation skill, this can divert user intent away from expected commands or activate the skill during unrelated review workflows, increasing the chance of unintended instruction influence or incorrect tool recommendations.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.