skills/kevinzai/cc-commander/ccc-seo/Gen Agent Trust Hub

ccc-seo

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of prompt injection or instructions to bypass safety guidelines was found. The skill maintains a consistent focus on SEO tasks.
  • [DATA_EXFILTRATION]: The skill integrates with several third-party SEO and analytics services (Google Search Console, SemRush, Ahrefs, PostHog, SerpAPI, DataForSEO). These are well-known technology services, and the data flows are consistent with the skill's stated purpose. The skill correctly instructs users to manage sensitive credentials via environment variables rather than hardcoding them.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. External tool usage is limited to standard CLI tools like curl, jq, and python3 for processing data from trusted APIs.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to analyze external web content (e.g., top-ranking SERP results in serp-analyzer). While this represents an ingestion point for untrusted data, it is a standard requirement for SEO analysis tools and does not pose an inherent risk given the absence of automated execution of that content.
  • [DYNAMIC_EXECUTION]: The skill utilizes standard programming environments (Node.js, Python) and build tools (npx) to perform legitimate SEO and analytics tasks, such as generating static sites or calculating statistical significance for A/B tests.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 05:35 AM
Security Audit — agent-trust-hub — ccc-seo