Back to skill

Security audit

Seo Content Pro

Security checks for vulnerabilities and agentic risk

Overview

This SEO writing skill is broadly coherent, but it includes an explicit AI-detector bypass tool and some under-disclosed external API and credential-handling risks.

Review this skill carefully before installing. Use it only for transparent, policy-compliant editing, not to misrepresent AI-generated content as human-authored or evade platform, academic, or publisher checks. Prefer GEMINI_API_KEY from a protected environment over --api-key, avoid sending confidential prompts or images to Gemini, and be aware that local output files may be overwritten when you choose an output path.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/generate_image.py:3
Finding

Unpinned Runtime Dependencies Create a Supply-Chain Risk

Content
View full analysis
=3.10" # dependencies = [ # "google-genai>=1.0.0", # "pillow>=10.0.0", # ] # /// ``` ### Technical Analysis The inline dependency metadata specifies only minimum versions for `google-genai` and `pillow`. It does not impose upper bounds, lock exact reviewed versions, or verify package hashes. When the script is executed through a compatible dependency-resolving runner such as the documented `uv run` workflow, the resolver may install a newer release that did not exist when the Skill was audited. Python packages can execute code during installation or import. Consequently, compromise of a dependency release or its distribution channel could turn an otherwise legitimate script invocation into arbitrary code execution. The audit did not find a currently embedded malicious dependency or an alternative package source. This finding concerns the absence of reproducible, integrity-verified dependency resolution. ### Attack Path 1. An attacker compromises a future compatible release of `google-genai`, `pillow`, or the package distribution channel. 2. The malicious release still satisfies the open-ended `>=` version constraint. 3. A user runs `generate_image.py` using a runner that automatically resolves the inline dependencies. 4. The runner downloads and installs the compromised release. 5. Malicious code executes during installation or when the script imports the package. 6. The payload operates with the privileges of the user running the Skill. ### Impact Assessment A compromised dependency could execute arbitrary code with the invoking user's privileges. Depending on that user's environment, the payload could access project files, environment variables such as `GEMINI_API_KEY`, writable user data, and network ...[truncated 281 chars]
Remediation
View remediation
", # "pillow==", # ] ``` 2. Generate and commit a lockfile containing the complete transitive dependency graph. 3. Use hash verification for downloaded distributions where the package-management workflow supports it. 4. Configure dependency resolution to use a trusted package index explicitly. 5. Update dependencies through a controlled process involving security review, automated vulnerability scanning, and regression testing. 6. Run image generation in a restricted environment with minimal filesystem access and only the required environment variables. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_image.py:54
Finding

Gemini API Key Can Be Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly promotes 'humanization' to bypass AI detectors, which is an evasion-oriented behavior unrelated to legitimate SEO assistance. Evasion tooling can be used to defeat trust and review mechanisms in publishing, education, or platform moderation contexts, making the skill materially more dangerous than a normal writing assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly promotes 'humanization' to bypass AI detectors, which is an evasion-oriented behavior unrelated to legitimate SEO assistance. Evasion tooling can be used to defeat trust and review mechanisms in publishing, education, or platform moderation contexts, making the skill materially more dangerous than a normal writing assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly promotes 'humanization' to bypass AI detectors, which is an evasion-oriented behavior unrelated to legitimate SEO assistance. Evasion tooling can be used to defeat trust and review mechanisms in publishing, education, or platform moderation contexts, making the skill materially more dangerous than a normal writing assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly promotes 'humanization' to bypass AI detectors, which is an evasion-oriented behavior unrelated to legitimate SEO assistance. Evasion tooling can be used to defeat trust and review mechanisms in publishing, education, or platform moderation contexts, making the skill materially more dangerous than a normal writing assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill explicitly promotes 'humanization' to bypass AI detectors, which is an evasion-oriented behavior unrelated to legitimate SEO assistance. Evasion tooling can be used to defeat trust and review mechanisms in publishing, education, or platform moderation contexts, making the skill materially more dangerous than a normal writing assistant.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly markets rewriting text to 'bypass AI detectors,' which is intentional evasion guidance. This can facilitate academic fraud, policy circumvention, deceptive publishing, and evasion of moderation or provenance checks, making it a high-risk misuse-enabling feature.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_image.py (reported line 23)May include surrounding context.

python
def get_api_key(provided_key: str | None) -> str | None:
    """Get API key from argument first, then environment."""
    if provided_key:
        return provided_key
    return os.environ.get("GEMINI_API_KEY")

Ssd 2

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file is framed and implemented as an AI-text evasion utility under benign 'humanize' language, which is deceptive by design. In a content/SEO skill, this is especially dangerous because it operationalizes content laundering at scale, potentially enabling fraud, policy evasion, plagiarism concealment, and reputational harm for downstream publishers.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises executable/scripted capabilities and file/environment interactions but does not declare an explicit tool scope such as permissions or allowed-tools. That makes the effective privilege boundary unclear to users and hosts, increasing the chance of unexpected file access or environment-variable use, especially since the document references local file inputs/outputs and API keys.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions encourage rewriting AI-generated text specifically to evade detection systems under a 'humanization' label. This is dangerous because it operationalizes deception rather than benign editing, and the SEO/content context makes mass production and distribution of disguised synthetic content especially scalable.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The humanization workflow is explicitly framed as making content appear natural in order to avoid AI detection, which is a clear misuse-enabling pattern. In an SEO automation skill, this can be applied at scale to flood search ecosystems or deceive reviewers about content provenance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to generate or edit images through a third-party Google Gemini API but does not warn that prompts and image inputs may be transmitted to an external service. In a content workflow, users may upload proprietary drafts, branding assets, or client images, so silent third-party transfer creates a meaningful privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script explicitly states its purpose is to transform AI-generated text to bypass detection, which is an evasion capability rather than a neutral formatting feature. In an SEO/content-generation skill, this increases misuse risk by helping users conceal AI provenance and defeat platform, academic, or publisher integrity controls.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The implementation goes beyond stylistic editing by stripping chatbot artifacts, citations, and ChatGPT/OpenAI tracking markers while describing the output as merely 'human-like.' That combination enables attribution removal and deception, making it easier to pass off generated material as original human-authored content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and all user-facing strings describe and emit output exclusively in Chinese, presenting the skill as a Chinese-only title generator. Under the policy rules, forcing a specific language without offering the user a language or locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a broad SEO content suite including AI humanization, image generation, multi-language support, content refresh, SEO scoring, and competitor analysis. This script implements only local title-template generation and a basic heuristic title score, with no content creation pipeline, image generation, multilingual handling, refresh logic, or competitor analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring is written entirely in Chinese and provides no indication that language is configurable or intentionally limited to a Chinese-only context. Per the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file advertises '竞品分析集成' as a feature, which commonly implies sending user-provided topics or content to an external analysis service or processing third-party data. The README provides no user-facing warning about possible network use, privacy considerations, or what data may be analyzed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Most of the skill documentation is in English, but the final sections switch to Chinese for author-support and feature documentation without warning or user choice. This can impose a language change on users unexpectedly instead of offering localized content explicitly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description at L003 describes SEO content creation, humanization, image generation, multi-language support, content refresh, SEO scoring, and competitor analysis, but the later documentation adds a separate AI title generator feature with scoring and A/B testing workflow. Title generation is related to SEO, but it is still an undocumented capability relative to the manifest’s stated feature set.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The package description advertises "multi-language support" but does not indicate whether language selection is user-driven or whether a default language/locale may be imposed. Because language/locale policy applies to all file types, this is a mild natural-language policy concern when no opt-in or choice is documented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The script reads the path provided by the user directly from disk via Path(args.input).read_text(), which is a file-access operation covered by the missing-warning rule for code files. There is no confirmation prompt, user-facing notice, or explanatory comment/docstring near the operation describing that the tool will open and process the specified file contents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The script's stated purpose is image generation/editing, but it also implements credential discovery from process environment via GEMINI_API_KEY. Accessing environment-held secrets is not directly implied by the skill manifest, which describes content and image features rather than credential-handling behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code writes transformed content to a user-specified output path, but it provides no explicit warning that an existing file may be overwritten or modified. Although the script logs the destination after writing, that does not disclose the risk beforehand or explain the data-changing behavior in a user-facing warning.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.