Is seo-skills/seo-audit-skill safe?
Yes. seo-skills/seo-audit-skill is safe to install. Oathe's behavioral security audit gave the seo-audit-skill skill by seo-skills a trust score of 86/100 with 5 findings, none critical or high.
https://github.com/seo-skills/seo-audit-skill
Is seo-skills/seo-audit-skill safe to install?
The seo-audit-skill (SEOmator) is a well-structured, legitimate SEO auditing tool with a clear use case and appropriate tool restrictions (Bash(seomator:*) only). No prompt injection attempts, exfiltration mechanisms, malicious npm scripts, git hooks, or unexpected network activity were detected; the only external connection during clone was to GitHub. The primary concern is that the Website Discovery guidance explicitly instructs agents to read .env files and environment variables to locate deployment URLs, which could inadvertently surface secrets in the agent's context or response.
What security issues were found in seo-skills/seo-audit-skill?
Category Scores
Findings (5)
MEDIUM Website Discovery instructs agent to read .env files -20 ▶
The SKILL.md Website Discovery section explicitly instructs the AI agent to 'Check for local dev server configurations (package.json scripts, .env files)' and 'Check environment variables for deployment URLs.' While the intent is to find the correct audit target URL, this guidance could cause the agent to read .env files and inadvertently surface API keys, database credentials, or other secrets in its response or context window.
LOW SKILL.md content duplicated verbatim 0 ▶
The SKILL.md content appears twice consecutively within the same file. Both copies are identical. This is likely a copy-paste artifact from maintaining two SKILL.md files (root and skill/ subdirectory), not a manipulation attempt, but the duplication wastes token budget and could cause instruction parsing issues in some agent runtimes.
LOW Playwright browser automation dependency -15 ▶
The skill depends on Playwright for Core Web Vitals and JavaScript rendering analysis. While this is a legitimate requirement for the stated functionality, Playwright grants the installed CLI full browser automation capability including network interception and JavaScript execution in arbitrary page contexts.
LOW Local audit database accumulates crawled site data -22 ▶
Audit results including page titles, meta descriptions, link text, and structured data from audited sites are stored in ~/.seomator/ SQLite databases by default. This data store could be accessed by other skills or processes sharing the filesystem, and persists across sessions.
INFO Sensitive file accesses were audit framework canary initialization 0 ▶
The filesystem events show accesses to .env, .ssh/id_rsa, .aws/credentials, .npmrc, .docker/config.json, and gcloud credentials at 22:27:20. These accesses occurred before the git clone at 22:27:25, confirming they are the Oathe audit framework's own canary file setup process. All canary files remain intact with no modifications.
Should I install seo-skills/seo-audit-skill?
Oathe's verdict for seo-skills/seo-audit-skill is SAFE with a trust score of 86/100. Recommendation: Install with caution.