Back to skill

Security audit

Emergence SEO GEO

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real SEO/GEO auditor, but its local script can make unrestricted network requests from the user's machine and silently weakens HTTPS validation.

Review before installing. Use it only for public websites you intend to audit, avoid private or internal URLs, and be aware that E2E mode may send target domains or prompts to external search providers through local tools. Treat audit results cautiously because the script can accept unauthenticated HTTPS content after a failed verified request.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/geo_audit.py:194
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geo_audit.py:42
Finding

TLS Certificate Verification Is Disabled on Retry

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

When HTTPS fetches fail, the script silently retries with certificate verification disabled via ssl._create_unverified_context(). That permits man-in-the-middle interception or tampering of fetched HTML, robots.txt, and metadata, causing the audit to trust unauthenticated content and potentially produce incorrect or attacker-influenced results.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the operator to run a local Python script and optionally invoke external search tooling, which implies shell execution and outbound network access, but it does not declare any explicit tool scope or permissions. This creates an authorization ambiguity where an agent or runtime may execute broader capabilities than a reviewer expects, increasing the risk of unintended command execution, network egress, or misuse of local environment resources.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest file is in scope for vague-trigger review, and the description says to use the skill to audit "any target domain's visibility, technical crawlability, and semantic authority" without specifying narrower activation conditions or exclusions. The lack of explicit trigger constraints or negative examples makes invocation boundaries ambiguous for common SEO or website-analysis requests.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · hub_manifest.json (reported line 14)May include surrounding context.

json
},
  "api": {
    "type": "openapi",
    "url": "https://api.emergence.science/openapi.json"
  },
  "discovery": {
    "content_index": "https://api.emergence.science/content/index.json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · hub_manifest.json (reported line 15)May include surrounding context.

json
},
  "api": {
    "type": "openapi",
    "url": "https://api.emergence.science/openapi.json"
  },
  "discovery": {
    "content_index": "https://api.emergence.science/content/index.json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · manifest.json (reported line 12)May include surrounding context.

json
},
  "api": {
    "type": "openapi",
    "url": "https://api.emergence.science/openapi.json"
  },
  "discovery": {
    "content_index": "https://api.emergence.science/content/index.json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · manifest.json (reported line 15)May include surrounding context.

json
},
  "api": {
    "type": "openapi",
    "url": "https://api.emergence.science/openapi.json"
  },
  "discovery": {
    "content_index": "https://api.emergence.science/content/index.json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill_manifest.json (reported line 19)May include surrounding context.

json
},
  "api": {
    "type": "openapi",
    "url": "https://api.emergence.science/openapi.json"
  },
  "discovery": {
    "content_index": "https://api.emergence.science/content/index.json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill_manifest.json (reported line 22)May include surrounding context.

json
},
  "api": {
    "type": "openapi",
    "url": "https://api.emergence.science/openapi.json"
  },
  "discovery": {
    "content_index": "https://api.emergence.science/content/index.json"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Retrying HTTPS requests without certificate validation and without a clear user warning weakens transport security and hides the downgrade from the operator. In this skill context, that makes the GEO/SEO audit easy to manipulate by a network attacker because all subsequent parsing and scoring rely on potentially forged responses.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill can execute locally installed external binaries (including a hard-coded user-specific fallback path) during auditing, which expands its capabilities from passive website inspection to local code/tool execution. In an agent environment, this is more dangerous because it can trigger unintended side effects, leak query data to third-party tools, or invoke an attacker-replaced binary if the expected executable path is not trustworthy.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/geo_audit.py (reported line 86)May include surrounding context.

python
# Check domain indexation
        cmd_index = [bx_path, "web", f"site:{domain}"]
        try:
            res = subprocess.run(cmd_index, capture_output=True, text=True, timeout=15)
            if res.returncode == 0:
                data = json.loads(res.stdout)
                results = data.get("web", {}).get("results", [])

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/geo_audit.py (reported line 135)May include surrounding context.

python
# Check domain indexation
        cmd_index = [bx_path, "web", f"site:{domain}"]
        try:
            res = subprocess.run(cmd_index, capture_output=True, text=True, timeout=15)
            if res.returncode == 0:
                data = json.loads(res.stdout)
                results = data.get("web", {}).get("results", [])

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/geo_audit.py (reported line 104)May include surrounding context.

python
if prompt:
            cmd_rank = [bx_path, "web", prompt]
            try:
                res = subprocess.run(cmd_rank, capture_output=True, text=True, timeout=15)
                rank = -1
                found_url = None
                if res.returncode == 0:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/geo_audit.py (reported line 154)May include surrounding context.

python
if prompt:
            cmd_rank = [bx_path, "web", prompt]
            try:
                res = subprocess.run(cmd_rank, capture_output=True, text=True, timeout=15)
                rank = -1
                found_url = None
                if res.returncode == 0:

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly advertises live queries to external search services but does not warn users that running the tool may transmit target domains, prompts, and related metadata to third-party providers. This is not inherently malicious, but it creates a transparency and privacy issue because operators may unintentionally disclose sensitive client, internal, or prelaunch information during use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file path and title indicate an English-specific version of the skill content (..._en.md), but the document provides no user-facing language choice or explanation for why English is required. Under the policy, forcing a specific language without opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/geo_audit.py:65