Back to plugin

Security audit

Agent SEO

Security checks for vulnerabilities and agentic risk

Overview

Agent SEO is a coherent SEO writing and analytics skill with disclosed file, web, and optional read-only data-provider behavior, but users should avoid feeding it confidential or unlicensed article examples.

Install only if you are comfortable with an SEO assistant that creates local drafts/reports, performs web research, and can optionally query analytics or SEO providers when you explicitly request those modes. Do not paste confidential business material or full third-party articles as style examples unless you have permission, and review fact-check corrections before allowing any existing file to be modified in place.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The fact-check section mixes a verification task with an instruction to apply corrections directly to the checked content. That creates an unsafe write path during what users may reasonably expect to be a review-only workflow, increasing the chance of unintended modification of drafts or source material if the agent is given broad file-write capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly instructs users to paste complete articles, including full content, without any guardrails about copyright, licensing, confidentiality, or sensitive information. In a skill context, this can lead users to upload proprietary company material or third-party content into the agent workspace, creating legal exposure and unintended data disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The quick-start section suggests including competitor articles as examples, but does not warn about copyright restrictions, terms-of-use limitations, or the risk of repurposing third-party content into model context. This can normalize ingesting unlicensed external material and may contaminate outputs or expose the organization to IP and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file explicitly instructs users to include full articles or 500+ word excerpts from external blog posts, which encourages substantial copyrighted-content reuse without any permission, licensing, or fair-use guidance. In an agent skill, this can cause the model or user workflow to reproduce protected material at scale, creating legal and compliance risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.