seo-dataforseo

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions to run an installation script at ./extensions/dataforseo/install.sh if the required extension is not found in the environment.
  • [COMMAND_EXECUTION]: The skill invokes a local script utility ${CLAUDE_PLUGIN_ROOT}/scripts/claude-seo to execute dataforseo_costs.py for API cost tracking, configuration, and budget guardrails.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection. Ingestion points: Untrusted data is ingested from Google search results, YouTube video comments (serp_youtube_video_comments_live_advanced), and AI visibility tools (ai_optimization_chat_gpt_scraper) as described in SKILL.md. Boundary markers: No explicit delimiters or boundary markers are defined to help the agent distinguish between its instructions and the retrieved third-party data. Capability inventory: The skill instructions include the capability to execute shell commands via the claude-seo wrapper and the extension installation script. Sanitization: There is no mention of sanitization, filtering, or validation of the retrieved content before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The installation process for the required DataForSEO extension via install.sh likely involves downloading external components, though no specific remote URLs were identified within the static analysis of the skill markdown files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:03 PM
Security Audit — agent-trust-hub — seo-dataforseo