Back to plugin

Security audit

Seo Keyword Research

Security checks for vulnerabilities and agentic risk

Overview

This SEO research skill is mostly coherent and transparent about using an AIsa API key, crawling public websites, and sending SEO inputs to AIsa/DataForSEO, though its invocation wording is broader than ideal.

Install only if you are comfortable providing an AIsa API key and sending SEO research inputs, crawled public page text, competitor domains, and prompts to AIsa/DataForSEO. Use it for SEO keyword research tasks, not general browsing or private content extraction, and avoid crawling internal, authenticated, customer, or confidential pages.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill clearly instructs the agent to use environment variables, read and write local files, and make network requests, yet it does not declare explicit permissions for those capabilities. This creates a trust and review gap: a harness or user may invoke the skill without understanding that local content and site data will be transmitted to external services and written to disk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation guidance goes beyond narrowly scoped SEO keyword research and explicitly says to use the skill when the user needs generic web search, research, source discovery, or content extraction. That broad trigger can cause the agent to select this skill for unrelated tasks, increasing the chance of unnecessary crawling, external API use, and data handling outside the intended security and policy boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger condition is overly broad because it includes generic 'web search, research, source discovery, or content extraction' tasks, which can cause the skill to activate outside narrow SEO keyword research. In context, that matters because activation leads to crawling websites and sending gathered content to external AIsa/DataForSEO endpoints, increasing the chance of unnecessary data collection and exfiltration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill directs the agent to transmit crawled site data and keyword research inputs to external AIsa/DataForSEO services. In this skill's context that behavior is expected, but it is still security-relevant because crawled pages may contain sensitive business information, internal strategy, customer data, or accidentally included secrets that would leave the local environment.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
Use these AIsa endpoints:

- Data APIs: `https://api.aisa.one/apis/v1/...`
- LLM gateway: `https://api.aisa.one/v1/chat/completions`

Never print or commit API keys. If the key is missing, ask the user to set `AISA_API_KEY`.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The LLM gateway is another external transmission path, distinct from the data API, and may receive prompts containing extracted website content, competitor lists, or internal strategy notes. Even if the provider is trusted, the skill lacks clear limits on what portions of crawled or local data can be forwarded, creating avoidable exposure risk.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
Use these AIsa endpoints:

- Data APIs: `https://api.aisa.one/apis/v1/...`
- LLM gateway: `https://api.aisa.one/v1/chat/completions`

Never print or commit API keys. If the key is missing, ask the user to set `AISA_API_KEY`.

Static analysis

No suspicious patterns detected.