Back to skill

Security audit

GEO Tracker

Security checks for vulnerabilities and agentic risk

Overview

This GEO tracking skill is coherent and purpose-aligned, but users should remember that their prompts and brand data are sent to third-party AI providers.

Install in a virtual environment, pin dependencies if possible, and only audit prompts or brand information you are comfortable sending to OpenAI, Perplexity, Google, and Anthropic. Treat the Google AI Overview and scheduling claims as limited: scheduling depends on OpenClaw cron, and Google AI Overview support is not implemented in the bundled scripts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis
Remediation
View remediation
anthropic== google-generativeai== ``` 2. Lock all transitive dependencies rather than only direct dependencies. Use a tool such as `pip-tools`, Poetry, or another reproducible dependency resolver. 3. Generate and verify cryptographic hashes, then install with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Explicitly use a trusted package index where operationally appropriate, and avoid unreviewed extra indexes: ```bash python3 -m pip install --index-url https://pypi.org/simple --require-hashes -r requirements.txt ``` 5. Retain the documented virtual-environment workflow and advise users not to install the dependencies with administrator or root privileges. 6. Review dependency updates before changing locked versions, including transitive dependency changes and relevant security advisories. 7. Update both `SKILL.md` and `README.md` so users consistently follow the hardened installation procedure. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Tainted flow: 'req' from os.environ.get (line 52, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/geo_query.py (reported line 57)May include surrounding context.

python
data=data,
        headers={"Authorization": f"Bearer {key}", "Content-Type": "application/json"},
    )
    with urllib.request.urlopen(req, timeout=30) as r:
        body = json.loads(r.read())
    text = body["choices"][0]["message"]["content"]
    return analyze_response("perplexity", text, brand)

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

The documented behavior overstates what the skill actually does, including unsupported engines and unimplemented batch or scheduling features. This is dangerous because operators may rely on controls, coverage, or workflows that do not exist, causing blind spots in monitoring and potentially leading users to expose data to external services under false assumptions about the skill’s capabilities and outputs.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/geo_query.py (reported line 195)May include surrounding context.

python
score for primary brand
    brand_results = [r for r in results[brand] if "error" not in r]
    if brand_results:
        avg = round(sum(r["visibility_score"] for r in brand_results) / len(brand_results))
        print(f"\n{'=' * 60}")
        print(f"🏆 Overall Visibility Score for {brand}: {avg}/100 ({score_label(avg)})")

    return results


def main():
    parser = argparse.ArgumentParser(description="GEO Query — Check brand visibility in AI engines")
    parser.add_argument("--brand", required=True, help="Brand name to track")
    parser.add_argument("--query", required=True, help="Search query to send to AI engines")
    parser.add_argument("--engines", default="chatgpt,perplexity,gemini,claude",
                        help="Comma-separated engines (chatgpt,perplexity,gemini,claude)")
    parser.add_argument("--competitors", default=None, help="Comma-separated competitor names")
    parser.add_argument("--json", action="store_true", help="Output raw JSON")
    args = parse

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises capabilities that involve environment variables, file access, and network access, but it does not declare any explicit tool scope or permissions boundaries. This is dangerous because users and reviewers cannot easily determine what the skill is allowed to access, increasing the risk of over-privileged execution, unintended data exposure, or misuse of credentials during audits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The scheduling guidance encourages recurring audits and report generation but does not warn that prompts, brand names, and related audit data will be transmitted to third-party AI providers and that reports will be written to disk. In this context, the omission is risky because scheduled operation can continuously exfiltrate potentially sensitive business intelligence and persist it locally without informed user consent or retention controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script forwards user-supplied queries and brand/competitor analysis content to multiple third-party AI providers without any in-file warning, consent gate, or data-classification check. If users include confidential campaign plans, customer data, or internal brand intelligence in prompts, that information may be disclosed outside the organization and retained by external services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/geo_query.py (reported line 53)May include surrounding context.

python
"messages": [{"role": "user", "content": prompt}],
    }).encode()
    req = urllib.request.Request(
        "https://api.perplexity.ai/chat/completions",
        data=data,
        headers={"Authorization": f"Bearer {key}", "Content-Type": "application/json"},
    )

Static analysis

No suspicious patterns detected.