suparank/research

Fail

Audited by Snyk on Feb 28, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.75). These point to unverified third‑party endpoints — a GitHub repo from an unfamiliar user and a Cloudflare Workers URL that the prompt instructs you to clone/run via npx — which are not official sources and could deliver malicious scripts if executed without code review.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). SKILL.md explicitly instructs the agent to call external seo-mcp MCP tools (e.g., mcp__seo-mcp__keyword_generator, mcp__seo-mcp__get_backlinks_list, mcp__seo-mcp__get_traffic) and even points to an external MCP endpoint (https://seo-mcp.cnych.workers.dev/sse) to fetch Ahrefs/backlink/traffic data — public third-party data the agent ingests and uses to drive keyword selection and strategy.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 28, 2026, 09:35 PM
Security Audit — snyk — suparank/research