jike-seo

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's code, instructions, and required credential (JIKE_SEO_API_KEY) are coherent with its stated purpose (a remote SEO keyword data service); nothing requests unrelated credentials or performs unexpected local persistence or downloads.

This skill appears to do what it says: it runs a bundled Python CLI that sends your keyword queries to the provider's API and requires an API key. Before installing: 1) Only provide a JIKE_SEO_API_KEY you trust to this skill — the key will be sent as a bearer token to the service. 2) Avoid querying sensitive or private phrases (they will be transmitted to the remote API). 3) The 'check' command prints a partially redacted API key — that output may appear in logs or conversation history, so avoid running it in shared logs if you need secrecy. 4) Confirm you trust the provider (dso100 / the listed domains) — the script contacts dso-dataserver.dso100.com and the SKILL.md references the service homepage. 5) If you need stronger assurance, review the provider's privacy policy and limit/rotate the API key if it is exposed.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.