jike-seo
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's code, instructions, and required credential (JIKE_SEO_API_KEY) are coherent with its stated purpose (a remote SEO keyword data service); nothing requests unrelated credentials or performs unexpected local persistence or downloads.
This skill appears to do what it says: it runs a bundled Python CLI that sends your keyword queries to the provider's API and requires an API key. Before installing: 1) Only provide a JIKE_SEO_API_KEY you trust to this skill — the key will be sent as a bearer token to the service. 2) Avoid querying sensitive or private phrases (they will be transmitted to the remote API). 3) The 'check' command prints a partially redacted API key — that output may appear in logs or conversation history, so avoid running it in shared logs if you need secrecy. 4) Confirm you trust the provider (dso100 / the listed domains) — the script contacts dso-dataserver.dso100.com and the SKILL.md references the service homepage. 5) If you need stronger assurance, review the provider's privacy policy and limit/rotate the API key if it is exposed.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
