suparank/research
Warn
Audited by Gen Agent Trust Hub on Feb 28, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill encourages the installation of a remote MCP server using the command
npx -y @anthropic-ai/mcp-remote https://seo-mcp.cnych.workers.dev/sse. This establishes a connection to an unverified third-party worker that can execute logic or process data externally. - [EXTERNAL_DOWNLOADS]: The documentation suggests cloning a repository from an unverified source
https://github.com/cnych/seo-mcp.gitto gain access to keyword research tools. This source is not associated with the skill author or a known trusted vendor. - [COMMAND_EXECUTION]: The skill provides ready-to-use shell commands for environment modification and repository cloning. If executed, these commands introduce external dependencies that have not been audited for security.
- [DATA_EXFILTRATION]: While not performing direct exfiltration, the recommended use of the
seo-mcptool involves sending project configuration data, such as site info, keywords, and competitor domains, to a third-party service hosted atcnych.workers.dev.
Audit Metadata