Back to skill

Security audit

LinkSwarm API

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill uses LinkSwarm’s external backlink API in a purpose-aligned way, but users should approve credit-spending and public SEO actions deliberately.

Install only if you are comfortable sharing site and backlink details with LinkSwarm and letting an agent use LinkSwarm credits. Require explicit approval before contributing link slots, requesting backlinks, or registering webhooks, and keep the API key private.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill clearly directs agents to register domains, verify sites, and interact with a third-party backlink network, but it does not prominently warn users that site metadata and potentially operational details will be transmitted to an external service. In an agent context, this omission matters because users may unknowingly expose owned domains, categories, and other configuration data to a third party.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The waitlist registration example transmits an email address to an external API. While ordinary and likely intended, it is still a real privacy-relevant external transmission that should be disclosed so users understand personal data is being shared with a third party.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

1. Get API Key

Register at https://linkswarm.ai/register/ or via API:

bash
curl -X POST https://api.linkswarm.ai/waitlist \
  -H "Content-Type: application/json" \
  -d '{"email": "your@email.com"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The waitlist registration example transmits an email address to an external API. While ordinary and likely intended, it is still a real privacy-relevant external transmission that should be disclosed so users understand personal data is being shared with a third party.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

1. Get API Key

Register at https://linkswarm.ai/register/ or via API:

bash
curl -X POST https://api.linkswarm.ai/waitlist \
  -H "Content-Type: application/json" \
  -d '{"email": "your@email.com"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation explains the credit system and autonomous workflow mechanics, but it does not clearly warn that requesting backlinks consumes credits and can trigger external actions affecting the user's sites and SEO posture. In an autonomous-agent setting, hidden costs and automated third-party changes can cause unexpected spend, link placements, and reputational or policy risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This code sends domain and category data to an external API using an authenticated request. The transmission itself is expected for the feature, but it is still security-relevant because it exposes user-controlled site information to a third party and should not occur without explicit disclosure and consent.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
headers = {"Authorization": f"Bearer {KEY}", "Content-Type": "application/json"}

# 1. Register new site
requests.post(f"{API}/v1/sites", headers=headers, json={
    "domain": "myagentsite.com",
    "categories": ["ai", "tools"]
})

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This request contributes a page URL and domain to the external LinkSwarm service, disclosing site structure and enabling an external system to coordinate link placement behavior. In an agent environment, such transmissions can have operational and SEO consequences if performed automatically without user awareness.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
})

# 2. Contribute to earn credits
requests.post(f"{API}/v1/pool/contribute", headers=headers, json={
    "domain": "myagentsite.com",
    "page_url": "/partners/"
})

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This request asks a third-party service to obtain backlinks for a target domain, which transmits site data externally and initiates actions outside the user's environment. That is dangerous in an autonomous setting because it can spend credits, alter external representations of the user's site, and create SEO or compliance risk without a clear consent checkpoint.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
})

# 3. Request backlinks
requests.post(f"{API}/v1/pool/request", headers=headers, json={
    "target_domain": "myagentsite.com",
    "anchor_text": "AI Tools Directory"
})

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

md
- Docs: https://linkswarm.ai/docs/
- Discord: https://discord.gg/6RzUpUbMFE
- API Status: https://api.linkswarm.ai/health

## Why LinkSwarm?

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:38