Back to skill

Security audit

GEO 营销方案生成器

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed marketing-plan generator that researches companies and creates Word/PPT files; the main risks are ordinary network, file-output, and credential-hygiene considerations rather than hidden or malicious behavior.

Install this if you want a WorkBuddy skill that researches clients and generates GEO proposal documents. Before running it, expect it to search the web, read any source documents you provide, and write Word/PPT files locally. Publishers using the included PUBLISH.md should create narrow GitHub tokens and avoid exposing them in terminals, logs, or screenshots.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The guide tells users to use a GitHub Personal Access Token as a password during push, but it provides no warning about least privilege, secure storage, or avoiding token exposure in shells, logs, and screenshots. This can lead inexperienced users to create over-scoped tokens or handle them unsafely, increasing the chance of credential leakage and repository compromise.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The documented trigger phrases are broad and overlap with ordinary user requests for marketing or GEO-related help, which can cause the skill to activate unintentionally. In an agent platform, accidental invocation can lead to unintended network research, file generation, and use of tool permissions without the user clearly intending to run this specific skill.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The README states that the skill performs online research and generates local .docx/.pptx artifacts, but it does not clearly disclose these actions to the end user at the point of use. This reduces informed consent and can surprise users with external data access or local file creation, which is particularly relevant because the skill has Bash, Read, Write, and Edit capabilities.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.