Back to skill

Security audit

seo

Security checks for vulnerabilities and agentic risk

Overview

This SEO skill is broadly scoped but its crawling, API use, credential checks, and drift history are disclosed and fit the stated SEO-audit purpose.

Install this if you want Codex to run SEO audits against websites and configured SEO providers. Before full audits, confirm the target URL, whether third-party crawling/API tools may be used, whether paid DataForSEO credits may be consumed, and where drift baselines or caches are stored if you monitor changes over time.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad generic terms such as SEO, audit, schema, sitemap, and page speed, which can cause the skill to auto-invoke in many unrelated conversations. Because this skill can drive external crawling, credential checks, and optional API-backed analysis, unintended invocation could lead to unnecessary network access, privacy surprises, or accidental execution of expensive or stateful actions.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill description and runtime guidance do not prominently warn users that analysis may trigger external website crawling, use third-party APIs, inspect configured credentials, or access/store drift baselines over time. This creates an informed-consent and privacy risk: users may invoke the skill without realizing it can touch external systems or retain comparison history tied to a URL.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The methodology labels foreign-language domains linking to English content (and vice versa) as likely spam without requiring regional context, multilingual site configuration, or user confirmation. This can bias audits against legitimate international backlinks, leading users to misclassify valid links as toxic and potentially remove or disavow beneficial signals.

Static analysis

No suspicious patterns detected.