Keyword Rank Monitor

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This SEO keyword monitoring skill is mostly coherent, but users should notice that it describes ongoing monitoring/history and package installs despite being presented as instruction-only.

This appears suitable for SEO keyword monitoring, but before installing, confirm whether it will store monitored keywords and ranking history, how alerts are delivered, and why the Python packages are needed for an instruction-only skill.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The user may be asked to install Python packages for a skill that is otherwise described as instruction-only.

Why it was flagged

The skill metadata inside SKILL.md lists pip dependencies even though the supplied registry/install section says there is no install spec and no code files are present.

Skill content
"install": [{ "id": "requests", "kind": "pip", "package": "requests" }, { "id": "pandas", "kind": "pip", "package": "pandas" }]
Recommendation

Only install the listed packages if you understand why they are needed, and prefer a version with a clear install spec and implementation details.

What this means

Your monitored keywords, products, competitors, and ranking history may be retained or reused for later reports and alerts.

Why it was flagged

The skill describes keyword history, recurring monitoring, and alerts, which imply stored monitoring state or reused context across time.

Skill content
查看这个关键词的排名历史;设置排名预警:跌出前 10 名时提醒;监控 50 个关键词,每小时更新 + 预警
Recommendation

Avoid entering sensitive business strategy terms unless you are comfortable with the skill retaining them for monitoring, and check whether storage and alert behavior are documented by the platform.