seobuild-onpage
Warn
Audited by Snyk on May 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's required workflow (e.g., SKILL.md Execution Protocol and scripts/research.py) explicitly fetches and parses live SERP and competitor content from third‑party sources (DataForSEO, WebSearch, Ahrefs/SEMRush, Reddit/Medium/YouTube/etc.), and the agent is instructed to read and use that untrusted, user‑generated/public content to set flags and drive decisions (QDD_SIGNAL, EMQ_REQUIRED, tributary generation, 301/410 recommendations), which creates a clear indirect prompt‑injection vector.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill's runtime research pipeline calls the DataForSEO live SERP API (https://dataforseo.com and its /v3/... endpoints) to fetch competitor SERP/content which is injected into the agent's briefs/prompts and is listed as a core dependency, so external responses directly control generation.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata