seo-geo

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes Python scripts in the scripts/ directory to perform SEO audits, keyword research, and competitive analysis. It also directs the agent to use standard shell commands like curl to inspect technical elements of target domains such as robots.txt and meta tags.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch HTML from target websites and to communicate with the DataForSEO API (api.dataforseo.com). These network interactions are fundamental to the skill's primary purpose of search optimization analysis.
  • [INDIRECT_PROMPT_INJECTION]: Because the skill crawls and audits external websites, it processes untrusted content from the web. This creates a surface where a malicious site could attempt to influence agent behavior through text or metadata. However, the skill's scripts utilize regex for specific tag extraction rather than general language model processing of the site content, which reduces the risk.
  • [CREDENTIALS_UNSAFE]: The skill manages DataForSEO API credentials through environment variables (DATAFORSEO_LOGIN and DATAFORSEO_PASSWORD). This is documented as a secure practice for handling authentication secrets within the skill's scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:52 PM
Security Audit — agent-trust-hub — seo-geo