Back to skill

Security audit

Google Generative Engine Optimisation (GEO / SEO)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent SEO assistant, but it needs review because its optional tooling and default external-data workflows can make broad network and third-party requests without strong safeguards.

Review before installing in an agent with network access or secrets. Use a scoped Apify token, approve each external crawl/scrape and any scheduled monitoring, avoid giving live account access unless needed, prefer redacted exports, and do not run the optional sitemap extractor against untrusted URLs without adding URL and private-network protections.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
tools/sitemap_extractor.py:1
Finding

Unrestricted Sitemap URL Fetch Enables Server-Side Request Forgery

Content
View full analysis

Vulnerability Details

File Location: tools/sitemap_extractor.py, lines 1-9
Vulnerability Type: Server-Side Request Forgery caused by unrestricted outbound requests
Risk Level: High

Vulnerable Code

python
#!/usr/bin/env python3
import sys, re, requests
url = sys.argv[1] if len(sys.argv) > 1 else ""
if not url:
    print("Usage: sitemap_extractor.py https://example.com/sitemap.xml")
    sys.exit(1)
txt = requests.get(url, timeout=20).text
for loc in re.findall(r"<loc>(.*?)</loc>", txt):
    print(loc)

Technical Analysis

The script passes a command-line URL directly to requests.get() without validating its scheme, hostname, resolved IP address, port, or redirect destination. It therefore permits requests to arbitrary network locations reachable from the agent runtime.

No controls reject loopback, private, reserved, or link-local destinations. The code also follows HTTP redirects by default, allowing an initially public URL to redirect to an internal service. A timeout limits request duration but does not limit response size, so the entire response is loaded into memory before parsing.

Although the script only prints content found between loc elements, an internal or attacker-controlled response can deliberately wrap sensitive information in those elements. The request itself can also be used for blind internal-service discovery or interaction with HTTP endpoints.

Attack Path

  1. An attacker supplies a sitemap URL pointing directly to an internal address, localhost service, cloud metadata endpoint, or attacker-controlled redirector.
  2. The user or agent invokes tools/sitemap_extractor.py with that URL.
  3. The script issues the request using the agent host's network identity and network access.
  4. If redirects are used, requests follows them automatically to the final internal destination.
  5. The complete response is read into memory.
  6. Any response ...[truncated 944 chars]
Remediation
View remediation

Remediation Suggestions

  1. Accept only explicitly permitted URL schemes, preferably https, with http enabled only when necessary.
  2. Parse the URL before use and reject embedded credentials, malformed hosts, unexpected ports, and non-HTTP schemes.
  3. Resolve the hostname and reject every loopback, private, link-local, multicast, reserved, unspecified, and otherwise non-public IP address.
  4. Prevent DNS-rebinding bypasses by connecting only to validated resolved addresses and checking all returned address records.
  5. Disable automatic redirects or validate the scheme, host, port, and resolved addresses at every redirect hop.
  6. Prefer restricting sitemap retrieval to the origin of the website explicitly approved by the user.
  7. Stream the response and enforce a strict maximum body size.
  8. Call raise_for_status() and accept only expected XML content types.
  9. Parse XML with a hardened parser rather than a regular expression, with external entity processing disabled.
  10. Run the utility in an environment with outbound network restrictions that deny access to internal and metadata ranges.

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Open-Ended Dependency Constraints Create Supply-Chain Exposure

Content
View full analysis

Vulnerability Details

File Location: requirements.txt, lines 1-2; installation is documented in INSTALL_FOR_AGENTS.md, lines 61-64
Vulnerability Type: Unbounded third-party dependency installation
Risk Level: Medium

Vulnerable Configuration

text
requests>=2.31.0
apify-client>=1.7.0

The documented installation procedure is:

bash
pip install -r requirements.txt

Technical Analysis

Both dependencies use minimum-version constraints without upper bounds, exact version pins, a reviewed lock file, or package hashes. Consequently, a future installation can retrieve versions that did not exist when the Skill was audited.

Package installation and later imports execute third-party package code with the privileges of the Python environment. The current package names do not exhibit an observed typosquatting issue, and the audit found no evidence that the presently referenced projects are malicious. The security issue is that the effective dependency set is mutable and lacks integrity verification.

Attack Path

  1. A future malicious, compromised, or otherwise unsafe package release is published under one of the permitted dependency names.
  2. The new version satisfies the open-ended minimum constraint.
  3. A user follows the documented setup command at INSTALL_FOR_AGENTS.md:61-64.
  4. The package resolver selects and downloads the unreviewed version from the configured package index.
  5. Package installation, import, or runtime behavior executes code from that release with the permissions of the agent's Python environment.
  6. The compromised dependency can access files, environment variables, network resources, and other capabilities available to that process.

Impact Assessment

A compromised dependency could execute code with the privileges of the user or service installing and running the Skill. Depending on the host configuration, this may expose API tokens in envir ...[truncated 290 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin each direct and transitive dependency to an exact reviewed version.
  2. Generate and commit a deterministic lock file using a dependency-management tool appropriate for the project.
  3. Record cryptographic hashes and install with hash enforcement, such as pip's --require-hashes mode.
  4. Configure installation to use an explicitly trusted package index.
  5. Review dependency updates before changing the lock file, including release provenance, maintainers, published artifacts, and security advisories.
  6. Use automated vulnerability and dependency-integrity scanning in the release process.
  7. Install and run optional tools in an isolated virtual environment or container with minimal filesystem, secret, and network permissions.
  8. Avoid installing apify-client unless the associated optional workflow is actually required.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This code chunk implements only a lightweight URL classifier using keyword checks in the URL string. That is much narrower than the declared purpose, which presents a comprehensive SEO and scraping/reporting skill. While URL classification could be a supporting component within an SEO workflow, the supplied code does not itself perform SEO audits, competitor research, backlink analysis, keyword mapping, scraping, or reporting. Therefore the description materially overstates the behavior of the provided code chunk.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · aeo-geo/ai-friendly-seo-master-workflow.md (reported line 230)May include surrounding context.

md
---

## 6. Output Rule

Never say:

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
55% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · integrations/apify.md (reported line 528)May include surrounding context.

md
1. Do not apologize dramatically.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README explicitly encourages users to provide sensitive analytics and business-platform exports or access, including Search Console, Analytics, and Google Business Profile data, but does not pair those requests with clear privacy, minimization, or handling warnings. In an agent skill context, this increases the chance that users expose account data, customer information, or business-sensitive metrics to an automated workflow without understanding scope, retention, or least-privilege expectations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill directs the agent to use environment variables and network-based resources like Apify, but it does not declare any explicit tool scope or permission boundaries. In permissive runtimes, this can lead to unreviewed access to local secrets and external services, increasing the chance of credential exposure or unintended outbound requests.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

The skill pushes the agent toward autonomous tool selection and data acquisition, including using Apify actors and related external sources before asking the user for broader inputs. While framed as convenience, this can reduce user awareness and approval over what services are contacted and what data is pulled, especially when coupled with token-based access.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

APIFY_API_TOKEN

text

Do not ask the user for a long list of APIs. If GSC, GA4, PageSpeed, Ahrefs, Semrush, Moz, backlink, local, SERP, trend, or crawler data is needed, first use Apify actors, Apify MCP, Apify datasets, or Apify-hosted export/connector workflows.

The normal start sequence is:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad phrases like 'Write AI-friendly content' and 'Make this AEO optimized' that can match ordinary writing or editing requests, causing the skill to activate outside clearly scoped SEO/AEO audit scenarios. Over-broad activation increases the chance that this persona overrides more appropriate task-specific instructions, leading to unintended content transformation, policy drift, or misuse of SEO-oriented workflows on unrelated user data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation examples include broad, natural-language phrases such as 'Make my website ready for ChatGPT / Gemini / Perplexity / Google AI' and 'Make my brand appear in AI answers,' which are likely to match ordinary user requests outside a tightly scoped intent. Overbroad triggers can cause unintended skill activation, expanding the attack surface and allowing this workflow to intercept requests that may belong to other tools or require different safeguards.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · aeo-geo/ai-search-readiness.md (reported line 164)May include surrounding context.

md
## Common Mistakes

Do not promise AI Overview inclusion. Do not claim ChatGPT/Perplexity/Gemini mentions without checking. Do not treat FAQs as the whole AEO strategy. Do not ignore crawlability, entity clarity, trust, or source-worthiness.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · integrations/native-agent-scraping.md (reported line 504)May include surrounding context.

md
## Common Mistakes

Do not promise AI Overview inclusion. Do not claim ChatGPT/Perplexity/Gemini mentions without checking. Do not treat FAQs as the whole AEO strategy. Do not ignore crawlability, entity clarity, trust, or source-worthiness.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · audit/conversion-seo-audit.md (reported line 193)May include surrounding context.

md
Confusing navigation
Slow page
Broken form
No confirmation message
No thank-you page
No follow-up automation
Too many competing CTAs

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger text says to use this workflow whenever a user asks for several broad SEO-related intents, but it does not define boundaries, exclusions, or prerequisites. In an agent environment, this can cause over-activation on loosely related requests and may launch scraping, competitor collection, or external data gathering beyond what the user clearly requested, increasing the risk of unintended data access, cost consumption, and scope creep.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The statement "Beyond SEO is now Apify-first" establishes a mandatory platform preference in natural language. Because the document directs the skill to prefer a specific service by default rather than offering the user a choice first, it creates a policy-style constraint without opt-in.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · integrations/apify-first-operating-policy.md (reported line 120)May include surrounding context.

  1. Authority/backlink actors after page/keyword strategy is known.
text

Do not burn credits by crawling huge sites or running hundreds of keywords without approval.

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file instructs the skill to collect business and review-related data from Maps/Places/Reviews sources, including phone numbers, addresses, and review snippets, but it does not warn users about privacy, platform terms, or responsible handling of scraped data. Under SQP-2 for markdown files, behaviors that could affect privacy should include an explicit warning.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation language is broad enough that the agent may default to Apify for many loosely related SEO requests, increasing unnecessary external data collection and third-party interactions without narrowly scoped user consent. In a skill centered on scraping, crawling, and competitor intelligence, this can expand data exposure, cost, and compliance risk even if the author likely intended convenience rather than abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow directs collection of reviews, social content, maps data, and third-party mentions, but the add-on section does not require a clear user notice that external scraping and analysis of third-party content may occur. Because this skill explicitly promotes broad collection across public platforms, the missing disclosure raises privacy, compliance, and expectation-management risks, especially where personal data or platform-restricted content could be incidentally processed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file describes the skill purpose and use cases, but it does not define specific activation phrases, boundaries, or exclusion conditions. Broad descriptions like 'SEO strategy for businesses serving multiple areas' and the generic use-case list could cause unintended invocation because there is no explicit trigger scope or negative examples.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · onboarding.md (reported line 102)May include surrounding context.

md
## 7. Token Handling

Never ask the user to paste tokens into normal content files.

Preferred:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The setup instructs the agent to activate the skill for broad, common SEO-related requests like SEO, backlinks, competitors, local SEO, or growth plans without clear exclusion criteria. This can cause over-activation or prompt hijacking of general business/marketing tasks, leading the agent to apply the skill in contexts where it is not the best fit and potentially to overreach into scraping or external-tool workflows unnecessarily.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly instructs checking environment variables containing API tokens and local export paths without requiring notice, consent, or least-privilege handling. This can cause an agent to inspect sensitive local credentials or filesystem metadata silently, which is dangerous in shared or semi-trusted environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The example course page /chatgpt-course-urdu-hindi/ and the requirement for 'language pages if Urdu/Hindi/regional language matters' introduce a specific language/locale bias in the skill guidance. Because the file does not pair this with an explicit user-choice or opt-in statement, it can be read as steering outputs toward particular languages without confirming the user's preferred locale.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes the skill's purpose and behavior but provides no explicit trigger phrases, invocation conditions, or exclusion criteria. Without clear scope or negative examples, the activation boundary is ambiguous and could lead to unintended invocation in broader SEO or website-audit contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The examples include queries tied to Pakistan and Arlington Heights, which by themselves are fine as examples, but the document provides no explicit note that language/location should be selected based on user intent or target market. Because SQP-3 covers locale-policy issues, this can be read as imposing a locale context without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L198 instructs use of the pattern "[topic] course Urdu/Hindi," which steers output toward specific languages. The document does not indicate that language choice should be based on user preference or a region-specific requirement, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.