Back to skill

Security audit

Keyword Research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed keyword-research workflow that uses local domain profiles and browser-based SEO tools, with some privacy and supply-chain considerations but no artifact-backed malicious behavior.

Before installing, be comfortable with the skill saving keyword-research profiles locally for future sessions and using logged-in browser-based SEO tools if you grant access. Prefer installing from a pinned version or reviewed commit when available, and delete the local profile files if you do not want business context retained.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:35
Finding

Unpinned Third-Party Installer and Mutable Repository Source

Content
View full analysis
Remediation
View remediation
add ``` 2. Pin the repository source to an immutable reviewed commit hash or cryptographically signed release rather than the mutable default branch. 3. Publish and document SHA-256 checksums or signed release attestations for distributed artifacts. 4. Recommend inspecting the resolved installer and skill contents before installation, particularly before running them in an environment with browser sessions, credentials, or sensitive files. 5. Where supported, use lockfiles, npm provenance, signature verification, and a trusted package registry configuration. 6. Run installation with least privilege in an isolated environment. Do not use an administrator or root account, and restrict filesystem, network, browser, and secret access until integrity verification succeeds. 7. Update the README to identify the exact installer version and repository revision reviewed by maintainers so that users can reproduce the audited installation. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is designed to retain and reuse business descriptors, competitors, regional targeting, languages, and tool-access status across sessions, but it provides no consent boundary, retention policy, or minimization guidance. Even if not overtly malicious, this creates durable cross-session profiling that can expose sensitive commercial information or surprise users who expect ephemeral handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to create and use a per-domain profile file containing business details, region, language, competitors, and tool-access information, but it does not require any explicit notice to the user that this data will be stored locally and reused later. Persistent collection without clear consent or disclosure creates a privacy and trust risk, especially because the stored data may reveal sensitive business context and account-capability metadata across sessions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The explicit goal of making the next session start with complete data means the skill intentionally persists session state across runs. Without a clear consent model, retention limit, or deletion path, this creates privacy risk and broadens the blast radius if the local environment is accessed by another process or user.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
### Step 3: Save or update the profile

After each run (or whenever new info is added), write back to the profile file immediately so the next session starts with complete data.

Profile format (JSON):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to immediately write back new information after each run establishes ongoing persistence of user-supplied data without requiring a contemporaneous warning or confirmation. This increases the chance that users disclose information in conversation that is silently retained for future sessions, creating an avoidable privacy and consent failure.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
- `"free"` — Free account; limited features (see skip rules)
- `"none"` — No account; skip all steps for that tool

If the profile directory does not exist, create it first: `mkdir -p ~/.claude/skills/keyword-research/data/`

### Tool skip rules

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
| Account tier | Step 2B behavior | Step 3 behavior |
|---------|------------|-----------|
| `"paid"` | Use Keyword Gap (full competitor gap analysis) | Use Keyword Magic Tool (unlimited queries) |
| `"free"` | Skip Keyword Gap; use Keyword Magic Tool (10 queries/day cap—watch usage) | Use Keyword Magic Tool (mind the cap) |
| `"none"` | Skip all Semrush; do not open any Semrush page | Same as left |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/gsc-operations.md (reported line 209)May include surrounding context.

The CDP proxy /click endpoint accepts CSS selectors only, not raw coordinates. For coordinate clicks, use /eval:

bash
curl -s -X POST "http://localhost:3456/eval?target={tabId}" \
  -d 'document.elementFromPoint(X, Y).click()'

Static analysis

No suspicious patterns detected.