Back to skill

Security audit

audit-report

Security checks for vulnerabilities and agentic risk

Overview

This is a reporting skill that uses disclosed SEO/audit data sources and does not include hidden execution, persistence, or credential collection.

Install this skill only for audit reports on sites and exports you are authorized to analyze. Review and approve any paid or third-party connector use, because those services may receive site, query, or SEO data through your configured accounts. The package also appears to reference missing supporting docs, so connector-selection behavior may depend on other Groundcrew files in the user's environment.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Content
- **Tier 1.** Google Suggest for expansion (unofficial endpoint; treat as hints, `confidence: low`). A SERP the user pastes or fetches is an observation for that query, locale, device, and date — record all four.
- **DataForSEO.** Paid, per-request. Read `dataforseo.md`; show the cost preflight and get approval for each batch.
- **Ahrefs MCP** (`https://api.ahrefs.com/mcp/mcp`, API key on a plan that includes MCP) and **Semrush MCP** (`https://mcp.semrush.com/v1/mcp`, OAuth or API key). Use only when the user already pays for the tool and has configured the MCP in their client. Label rows `source: "ahrefs"` / `"semrush"`, `confidence` per the vendor's own accuracy notes; these are third-party estimates, not the user's own data.
- **TrustGrowth.** `keywords` (typed opportunities with volume, difficulty, intent, current position, scores) for the verified site. SERP snapshots per keyword are scheduled (TEC-7796).

### `~~link database` — backlinks and authority
Confidence
15% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Static analysis

No suspicious patterns detected.