competitive-seo-intel

Fail

Audited by Snyk on Jul 1, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). The skills.sh page itself is a content/listing page (not a direct .exe download), but it includes an npx install command that would execute code from an npm package published under an individual/unverified username — installing/running untrusted NPX/NPM packages is a potential malware vector unless the package and author are verified.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.78). 该技能在“收集竞品数据/技术评估/GEO/AI 引用分析”步骤中会对用户提供的竞品网址进行运行时抓取与内容读取(如分析竞品页面、外链来源页面、以及在 AI 系统中测试竞品内容),从而把“竞品网站/第三方网页的可读正文”作为自由文本喂入 LLM 上下文,属于公共网页/第三方内容注入风险。

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 1, 2026, 12:26 PM
Issues
2
Security Audit — snyk — competitive-seo-intel