Back to skill

Security audit

LaunchRanked SEO

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent SEO and AI-search guidance skill that uses public site checks and optional signed-in LaunchRanked reports, with sensitive actions mostly disclosed and user-gated.

Install this if you want an agent to audit and modify a website for SEO or AI-search visibility. Expect it to use LaunchRanked tools against public deployed URLs, and only connect the optional signed-in reports if you are comfortable sharing account-linked SEO/visibility data with that service. Review proposed noindex, robots.txt, canonical, redirect, and URL-structure changes before applying them because those can affect search traffic.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · references/frameworks.md (reported line 13)May include surrounding context.

md
- **noindex**: `robots: { index: false, follow: true }`.
- **Sitemap / robots**: `app/sitemap.ts` (returns `MetadataRoute.Sitemap`) and `app/robots.ts` (returns `MetadataRoute.Robots`, including `sitemap: "https://example.com/sitemap.xml"`).
- **OG image**: `app/opengraph-image.tsx` (or per route segment) using `ImageResponse` from `next/og`.
- **JSON-LD**: in the page component, `<script type="application/ld+json" dangerouslySetInnerHTML={{ __html: JSON.stringify(data).replace(/</g, "\\u003c") }} />`.
- **llms.txt**: `public/llms.txt`, or `app/llms.txt/route.ts` returning `text/plain` if it should be generated.
- **lang**: `<html lang="en">` in the root layout.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is broadly scoped around common requests like improving SEO, fixing metadata, auditing a site, and planning launches, which can cause the agent to invoke this skill for many generic web-development or marketing queries. Over-broad invocation increases the chance of unnecessary external tool use and unintended repo modifications on deployed/public URLs, especially because the skill encourages live-site inspection and code changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document repeatedly instructs implementers to set lang="en" or equivalent English locale defaults across frameworks. This is a natural-language locale policy constraint presented as a default without offering a user choice or documenting why English is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.