subkeyword-injector

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core SEO-editing purpose is coherent, and the documented agent-browser dependency appears legitimate. The main risk is the required 'GSC MCP' dependency: no official Google-published MCP was identified, so the skill implicitly asks users to trust third-party MCP servers with Search Console data and possibly OAuth tokens. This is not confirmed malware, but the unresolved provenance and credential-routing risk make the skill medium risk overall.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 06:30 PM
Package URL
pkg:socket/skills-sh/younesbenallal%2Fseo-skills%2Fsubkeyword-injector%2F@ce17b111fdba8590b9a8527067e7edee872f382e