Back to skill

Security audit

Seo Audit

Security checks for vulnerabilities and agentic risk

Overview

This SEO audit skill is a coherent, disclosed tool that reads chosen website build files and optionally checks a provided live site, with no evidence of hidden persistence, credential use, or exfiltration.

Install if you want an SEO/GEO audit helper. Run the local audit only against the intended build output directory, and run the live audit only on sites you are authorized to test. Review proposed source changes before applying them, especially robots.txt, llms.txt, canonical URLs, and crawler-access recommendations because they can affect search and AI crawler visibility.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The README suggests invoking the skill with very broad, everyday phrases such as 'audit this site's SEO' or 'help me improve SEO score.' In environments that auto-route based on natural-language matching, these generic triggers can cause the skill to activate unintentionally on loosely related requests, potentially leading to unsolicited network access, file inspection, or modifications beyond what the user intended.

Static analysis

No suspicious patterns detected.