Back to skill

Security audit

SEO优化检查器

Security checks for vulnerabilities and agentic risk

Overview

This SEO checker appears purpose-built, but it needs review because optional AI mode can send fetched webpage text and URLs to OpenAI without a clear warning, and URL fetching is not limited to public sites.

Install only if you are comfortable running a local SEO checker that makes outbound HTTP requests. Use it on public pages you control or are allowed to audit. Avoid private, staging, intranet, localhost, cloud-metadata, or sensitive pages, especially with --ai enabled, because AI mode can send page text and the URL to OpenAI. Consider pinning dependencies before installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
seo_checker.py:20
Finding

Unrestricted URL Fetching Enables SSRF and External Disclosure of Retrieved Content

Content
View full analysis
tuple[requests.Response, float]: """获取页面并记录耗时""" start = time.time() resp = requests.get( url, headers={ "User-Agent": ( "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) " "AppleWebKit/537.36 (KHTML, like Gecko) " "Chrome/120.0.0.0 Safari/537.36" ), }, timeout=timeout, allow_redirects=True, ) elapsed = time.time() - start return resp, elapsed ``` ```python def ai_analysis(url: str, raw_html: str) -> str: """调用 AI 进行增强分析""" try: from openai import OpenAI except ImportError: return "错误: 需要安装 openai 库。运行: pip install openai" api_key = os.environ.get("OPENAI_API_KEY") if not api_key: return "错误: 请设置环境变量 OPENAI_API_KEY" model = os.environ.get("OPENAI_MODEL", "gpt-4o-mini") client = OpenAI(api_key=api_key) # 提取前 5000 字符进行 AI 分析 text = BeautifulSoup(raw_html, "html.parser").get_text(separator=" ", strip=True)[:5000] prompt = textwrap.dedent(f"""\ 你是一位 SEO 专家。请对以下网页内容进行 SEO 分析,给出具体的优化建议。 URL: {url} 页面内容(前5000字符): {text} 请以 Markdown 格式输出分析报告,包含以下内容: 1. 内容质量评估(原创性、价值性、相关性) 2. 关键词策略建议(推荐的核心关键词) 3. 内容优化建议(标题改进、内容补充方向) 4. 用户体验建议(可读性、结构、CTA等) 5. 优先级排序(哪些改进最紧急) 注意:输出不要太长,但要具体可执行。 """) resp = client.chat.completions.create( model=model, messages=[ {"role": "system", "content": "你是一位资深的 SEO 优化专家,精通百度 SEO 和 Google SEO。"}, {"role": "user", "content": prompt}, ], temperature=0.5, ) return resp.choices[0].message.content or "" ``` ```py ...[truncated 3859 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:55
Finding

Unpinned Third-Party Dependencies Create a Mutable Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

README 鼓励启用 AI 模式并要求配置 OPENAI_API_KEY,但未明确告知用户:被检测网页的内容、元数据或分析结果可能会发送到外部 AI 服务。这会造成数据出境与第三方共享风险,尤其当用户检测的是内网页面、未公开页面或含敏感业务内容的站点时,可能导致隐私、合规或保密问题。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises network access, environment variable use, and file output behavior in its documentation, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a transparency and policy-enforcement gap: a host agent may permit broader capabilities than the user expects, including outbound requests to arbitrary URLs and access to secrets like OPENAI_API_KEY.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The top-level description specifies the tool in Chinese, and the AI prompt also instructs the model to return the analysis report in Chinese-language context without any opt-in or locale selection. This creates a natural-language locale constraint that is not documented as optional or region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The optional AI enhancement transmits the page URL and up to 5000 characters of extracted page text to an external LLM service. For an SEO checker, this creates a real data-exfiltration/privacy boundary crossing that is broader than basic local page inspection, especially when users analyze private, staging, internal, or sensitive pages.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

该技能的核心用途是对网页做SEO诊断,主流程已能通过本地解析HTML完成大部分声明的检查项。L247-L256 引入外部AI客户端并读取环境变量中的API密钥,属于额外的凭证使用与第三方服务调用能力,和“输入网址输出SEO诊断报告”的基础目的并不直接对应。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code sends page content and the target URL to a third-party API during AI analysis without any explicit user-facing warning at the point of use. Users may reasonably expect an SEO checker to inspect content locally, so undisclosed transmission can expose confidential content, internal URLs, or regulated data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The AI analysis forwards raw extracted webpage text to the external model with only a length cap, not meaningful data minimization or sensitivity filtering. Webpages may contain user-generated content, internal business data, emails, access hints, or other sensitive information, so this can leak data outside the expected processing boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt content and system message instruct the model in Chinese and frame the analysis for Chinese-language output, but the user is not given any language or locale choice. This is a policy concern because the skill imposes a specific language by default rather than making it configurable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

全文说明均以中文呈现,且未提供语言选择、英文版本入口或注明该技能仅面向中文用户/中文市场。按语言/locale 政策要求,若技能实际上面向更广泛用户,强制单一语言而无用户选择可能构成自然语言层面的政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.