Back to skill

Security audit

SocQ SEO Research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed SocQ SEO research integration that sends user-directed public SEO queries to SocQ and uses a SocQ API key, with cost and credential guardrails documented.

Install this only if you intend to use SocQ for SEO research and are comfortable sending the requested domains, keywords, locales, and filters to SocQ under your SOCQ_API_KEY. Use spending limits and confirm larger paid runs, avoid placing the key in command lines or prompts, and prefer a pinned or preinstalled @socq/cli instead of ad hoc npx execution when possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding
The skill permits use of `npx` and installs `@socq/cli` without any version pinning or integrity constraint. That creates a supply-chain risk: a future malicious or compromised package release could be fetched and executed implicitly in the agent environment.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding
The instruction to use `npx @socq/cli` will resolve and execute the latest package version by default unless a version is pinned. In agentic environments this is risky because it enables unreviewed code changes from the upstream package registry to affect execution at run time.

External Transmission

Medium
Category
Data Exfiltration
Content
value: "socq"
      description: "Hosted SocQ SEO data tools"
      transport: "streamable_http"
      url: "https://api.socq.ai/mcp?platforms=seo"
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
value: "socq"
      description: "Hosted SocQ SEO data tools"
      transport: "streamable_http"
      url: "https://api.socq.ai/mcp?platforms=seo"
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:32