seo-dataforseo

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Python utility dataforseo_costs.py via the claude-seo run command to manage API credit spending.\n- [COMMAND_EXECUTION]: The skill requires the user to run a local installation shell script located at ./extensions/dataforseo/install.sh as a prerequisite for operation.\n- [PROMPT_INJECTION]: The skill processes untrusted third-party data, establishing an attack surface for indirect prompt injection.\n
  • Ingestion points: Data is ingested from external environments via tools such as serp_organic_live_advanced (SERP results), serp_youtube_video_comments_live_advanced (YouTube comments), on_page_content_parsing (website content), and ai_optimization_chat_gpt_scraper (AI-generated search results).\n
  • Boundary markers: The skill does not specify the use of delimiters or instructions to ignore commands within the ingested external data.\n
  • Capability inventory: The skill can execute local system commands and perform network-based API requests.\n
  • Sanitization: No sanitization or validation of the processed external content is described in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 09:13 AM
Security Audit — agent-trust-hub — seo-dataforseo