seobuild-onpage

Warn

Audited by Snyk on May 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's required workflow (e.g., SKILL.md Execution Protocol and scripts/research.py) explicitly fetches and parses live SERP and competitor content from third‑party sources (DataForSEO, WebSearch, Ahrefs/SEMRush, Reddit/Medium/YouTube/etc.), and the agent is instructed to read and use that untrusted, user‑generated/public content to set flags and drive decisions (QDD_SIGNAL, EMQ_REQUIRED, tributary generation, 301/410 recommendations), which creates a clear indirect prompt‑injection vector.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill's runtime research pipeline calls the DataForSEO live SERP API (https://dataforseo.com and its /v3/... endpoints) to fetch competitor SERP/content which is injected into the agent's briefs/prompts and is listed as a core dependency, so external responses directly control generation.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 8, 2026, 12:04 AM
Issues
2
Security Audit — snyk — seobuild-onpage