ai-seo

Fail

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to clone an external repository (github.com/AminForou/mcp-gsc) and execute its contents using Python. This practice involves downloading and running unverified code from a third-party source.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external SEO tools and APIs, including DataForSEO, Google Search Console, and Semrush. This creates a surface for indirect prompt injection, as malicious instructions embedded in search data or competitor content could influence the agent.
  • Ingestion points: DataForSEO, Google Search Console, and Semrush APIs.
  • Boundary markers: None provided to separate untrusted data from instructions.
  • Capability inventory: The skill environment allows shell access for adding MCP servers, cloning repositories, and installing packages.
  • Sanitization: No evidence of data validation or sanitization is present in the instructions.
  • [COMMAND_EXECUTION]: The skill includes shell commands to modify the agent's environment by adding MCP servers and installing external dependencies.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 3, 2026, 01:31 AM
Security Audit — agent-trust-hub — ai-seo