suparank/research

Warn

Audited by Gen Agent Trust Hub on Feb 28, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill encourages the installation of a remote MCP server using the command npx -y @anthropic-ai/mcp-remote https://seo-mcp.cnych.workers.dev/sse. This establishes a connection to an unverified third-party worker that can execute logic or process data externally.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests cloning a repository from an unverified source https://github.com/cnych/seo-mcp.git to gain access to keyword research tools. This source is not associated with the skill author or a known trusted vendor.
  • [COMMAND_EXECUTION]: The skill provides ready-to-use shell commands for environment modification and repository cloning. If executed, these commands introduce external dependencies that have not been audited for security.
  • [DATA_EXFILTRATION]: While not performing direct exfiltration, the recommended use of the seo-mcp tool involves sending project configuration data, such as site info, keywords, and competitor domains, to a third-party service hosted at cnych.workers.dev.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 09:35 PM
Security Audit — agent-trust-hub — suparank/research