ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      geoly-geo

      Safety Report

      Brand Visibility Overview

      @geoly-geo

      Monitor your brand's AI visibility across ChatGPT, Perplexity, Gemini, Grok, and Google AI. Powered by GEOly AI — get AIGVR scores, mention counts, and platf...

      98Downloads
      0Installs
      0Stars
      1Versions
      Customer Support1,744Monitoring & Logging1,579AI & Machine Learning1,383

      Security Analysis

      medium confidence
      Suspicious

      The skill claims to call a third-party GEOly AI MCP API to fetch brand visibility data but provides no source/homepage, declares no credentials, and gives minimal instructions about data or auth—this mismatch is suspicious and needs clarification before use.

      Feb 27, 20261 files3 concerns
      Purpose & Capabilityconcern

      The skill's stated purpose is to connect to GEOly AI's MCP (https://app.geoly.ai/api/mcp) and fetch brand visibility metrics. Yet the skill declares no source/homepage, no owner contact, and no required credentials. Calling a third‑party API for proprietary metrics normally requires an API key or account; the absence of any credential requirement is inconsistent with the claimed capability.

      Instruction Scopeconcern

      SKILL.md explicitly instructs the agent to connect to a specific external endpoint and 'invoke the Brand Overview tool' but gives no details on authentication, rate limits, what input is sent, or how returned data is validated. The instructions permit sending user brand identifiers to an unknown external service, which could expose sensitive business data.

      Install Mechanismok

      This is an instruction-only skill with no install spec and no code files, so it does not write additional binaries or archives to disk. That keeps installation risk low.

      Credentialsconcern

      No environment variables, credentials, or config paths are declared despite the need to contact a third-party API. This is disproportionate: either the endpoint is public (unusual for proprietary visibility data) or the skill omits the required credential declarations, which could hide where secrets must be stored or transmitted.

      Persistence & Privilegeok

      The skill does not request always:true and is user-invocable only. Autonomous invocation is allowed (the platform default) but not combined with any elevated persistence or cross-skill configuration modifications.

      Guidance

      Before installing, ask the publisher for: (1) the skill's source code or homepage and a verifiable owner identity for geoly.ai; (2) whether the API endpoint requires authentication and, if so, what credentials you'll need (the skill should declare required env vars); (3) what exact data the agent will send to the external endpoint (brand names, IDs, customer data) and the vendor's data handling/privacy policy; (4) whether you can review responses or run the calls in a sandboxed environment first. If the vendor cannot provide clear docs or requires you to send sensitive data without explicit auth details, avoid enabling the skill or restrict its network egress until you can verify it.

      Latest Release

      v1.0.0

      Initial release: Brand overview dashboard via GEOly AI MCP, supporting AIGVR score, mentions & platform distribution

      Popular Skills

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Summarize

      @summarize · 415 stars

      Published by @geoly-geo on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]