scrapebox-seo-automation-tool
Fail
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: CRITICALDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill references a malicious URL 'https://api.proxyservice.com' in the Proxy Sources Integration section. This domain is currently blacklisted by security scanners and poses a risk of data exfiltration or malicious communication if used as a proxy endpoint.
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to download and run 'ScrapeBoxSetup.exe' from external sources. While presented as a legitimate tool, automated AV scanners have flagged the associated SKILL.md file as containing suspicious HTTP request patterns.
- [COMMAND_EXECUTION]: The documentation provides a batch script example that executes 'ScrapeBox.exe' with various command-line arguments to automate rank checking and data export. This allows for arbitrary command execution within the context of the automation workflow.
- [PROMPT_INJECTION]: The skill is designed to ingest large volumes of untrusted data from search engines and third-party websites (URLs, keywords, blog content, and email addresses), which presents a high risk of indirect prompt injection.
- Ingestion points: Harvester, Backlink Extractor, and Email Extractor tools in SKILL.md.
- Boundary markers: None present; the skill lacks delimiters or instructions to ignore malicious content found within scraped data.
- Capability inventory: The skill has the ability to execute shell commands via batch scripts and perform broad network operations.
- Sanitization: No sanitization or validation logic is mentioned for the harvested content before it is processed or used in outreach templates.
- [COMMAND_EXECUTION]: The installation instructions require the user to run the setup and the application with administrative privileges on Windows, which increases the potential impact of any malicious behavior.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata