Back to skill

Security audit

seo-audit

Security checks for vulnerabilities and agentic risk

Overview

This skill performs a disclosed, bounded SEO audit workflow, though users should be aware it can crawl many pages and write local reports.

Install this only if you want a full SEO audit tool. Before running it, provide a specific URL you are authorized to test and expect network crawling, local report files, possible screenshots, and optional use of configured SEO or Google credentials.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description uses broad trigger phrases like 'audit', 'analyze my site', and 'website health check' for a high-impact skill that can crawl up to 500 pages, spawn many subagents, and write artifacts to disk. This creates a real risk of unintended invocation, causing network activity, resource consumption, and file generation when a user may have meant a lighter analysis.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill lacks an explicit upfront warning that it may crawl up to 500 pages, make concurrent requests, invoke many subagents, capture screenshots, and persist audit artifacts under a local directory. Without clear disclosure, users may unknowingly trigger extensive external interactions and local file creation, which can have privacy, consent, cost, and operational consequences.

Static analysis

No suspicious patterns detected.