Back to skill

Security audit

SEO (Site Audit + Content Writer + Competitor Analysis)

Security checks for vulnerabilities and agentic risk

Overview

This SEO skill is a documentation-based assistant that stores disclosed local SEO preferences and history, with no evidence of hidden execution or data theft.

Before installing, understand that the skill may keep SEO preferences, site profiles, audit history, keyword tracking, and drafts under ~/Clawic/data/seo/. Review or delete that folder if you do not want prior business context reused, and avoid asking it to store confidential strategy unless that persistence is desired.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
| noindex on a robots.txt-blocked page | Google never crawls it, never sees the noindex | Allow crawl until deindexed, then block |
| Changing URLs without 301s | Links and authority now point at 404s | Map every old URL to its closest new match |
| Buying links or PBNs | Payment and network footprints → manual action | Earn links via assets and digital PR |
| Reporting rank without checking the rendered SERP | #1 under an AI Overview and four ads earns a fraction of historical #1 clicks | Check pixel position, not just rank |
| Judging index coverage with `site:domain.com` | The operator is an estimate and excludes results Google chooses to hide | Page indexing report + URL Inspection |
| Re-requesting indexing for the same URL repeatedly | The queue is not a priority auction; nothing accelerates | Fix the reason it was not indexed (quality, duplicate, discovery) |
| Fixing every warning a crawler emits | Crawl tools flag non-signals (meta keywords, long titles on pages with no impressions) | Rank issues by the traffic at stake, then fix |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · audits.md (reported line 76)May include surrounding context.

  1. Measurement plan — the GSC/analytics view that will show whether it worked, and when
text

Write the exact change, never the category: "add `<link rel=canonical>` self-reference to the product template" beats "fix canonicalization". Every recommendation a developer can ticket without asking a question.

## Audit Traps

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup explicitly instructs the agent to read persistent preference and history files and apply their contents automatically, but provides no user-facing notice or consent flow for this ongoing data use. It also directs the agent to persist new preferences and work context over time, which can create silent accumulation of potentially sensitive business information, behavioral preferences, and prior project history.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions tell the agent to write user-declared preferences, constraints, and corrections into persistent files without warning the user that their statements may be retained across sessions. In an SEO context, this can silently store commercially sensitive details such as site strategy, rejected recommendations, platform choices, and operating constraints, increasing privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The configuration table sets target_market to a default of en-US and says defaults apply until the user states a preference. That imposes a specific locale and spelling variant by default rather than first obtaining the user's language/market choice, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example configuration sets target_market: en-GB and describes it as the locale used for SERP checks and spelling. In a reusable skill template, this can be read as prescribing a fixed locale rather than offering user choice, which conflicts with the language/locale policy unless clearly opt-in or region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.