ccc-seo
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of prompt injection or instructions to bypass safety guidelines was found. The skill maintains a consistent focus on SEO tasks.
- [DATA_EXFILTRATION]: The skill integrates with several third-party SEO and analytics services (Google Search Console, SemRush, Ahrefs, PostHog, SerpAPI, DataForSEO). These are well-known technology services, and the data flows are consistent with the skill's stated purpose. The skill correctly instructs users to manage sensitive credentials via environment variables rather than hardcoding them.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. External tool usage is limited to standard CLI tools like
curl,jq, andpython3for processing data from trusted APIs. - [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to analyze external web content (e.g., top-ranking SERP results in
serp-analyzer). While this represents an ingestion point for untrusted data, it is a standard requirement for SEO analysis tools and does not pose an inherent risk given the absence of automated execution of that content. - [DYNAMIC_EXECUTION]: The skill utilizes standard programming environments (Node.js, Python) and build tools (npx) to perform legitimate SEO and analytics tasks, such as generating static sites or calculating statistical significance for A/B tests.
Audit Metadata