dataforseo

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill integration targets a well-known and legitimate SEO data service (dataforseo.com) via its official API endpoint. This communication is consistent with the skill's stated purpose of querying keyword rankings and SEO performance metrics.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were identified. The skill correctly instructs the use of environment variables (DATAFORSEO_LOGIN, DATAFORSEO_PASSWORD) to handle authentication securely.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests data from an external API (DataForSEO tasks result items). However, this risk is assessed as negligible because the data consists of structured SEO metrics, and the skill does not expose dangerous capabilities such as arbitrary code execution or file system write access that could be leveraged by an attacker-controlled API response.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 04:50 AM
Security Audit — agent-trust-hub — dataforseo