Skip to content
Report library
Purpose / Writing

Ai Seo Skill Security Audit

What the author says it does (original text)

When the user wants to optimize content for AI search engines, get cited by LLMs, or appear in AI-generated answers. Also use when the user mentions 'AI SEO,' 'AEO,' 'GEO,' 'LLMO,' 'answer engine optimization,' 'generative engine optimization,' 'LLM optimization,' 'AI Overviews,' 'optimize for ChatGPT,' 'optimize for Perplexity,' 'AI citations,' 'AI visibility,' 'zero-click search,' 'how do I show

Independent security check

Security risks found

Files checked
10
Risks found
5
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.Risks found: 2
Medium risk

The Skill recommends executing an unpinned npx package

Source references: 3
What we found

The `npx is-agentic` command can download and immediately execute the currently published package. The Skill does not pin a version, verify a checksum, or require inspection before execution.

Why this matters

If the package, publisher account, or dependency chain is compromised, code runs with the user's permissions and could read project files, environment variables, or credentials and modify local files. The domain is also provided to the tool.

This is an actionable command the reference tells the user to run, not merely an illustrative code sample. It has no `@version` or integrity check, and npx can download and immediately execute the current package when needed. The risk arises if the user chooses and runs the CLI option; impact depends on the package contents at that time and the user's local permissions. The user can choose the web option or request a pinned version, source, and checksum.

references/agent-readiness.md:7In the instructionsOpen original file
| Tool | Run it | Method ||---|---|---|| **Is Agentic** (Vercel + Ora) | `npx is-agentic yourdomain.com` or [is-agentic.com](https://is-agentic.com) | 100+ checks; Essential checks carry most of the score; Recommended checks activate only when evidence shows you have that surface (API, MCP server, commerce); not-applicable checks are excluded, not failed; includes an observed agent journey showing where a real agent hit friction || **Frase Agent Readiness Checker** | [frase.io/tools/agent-readiness](https://www.frase.io/tools/agent-readiness) | Access / Discovery / Parseability triad; 80+ = agents can reliably use the site, 60–79 = solid with gaps, <60 = real access problems |
Show 2 other places
references/agent-readiness.md:9In the instructionsOpen original file
|---|---|---|| **Is Agentic** (Vercel + Ora) | `npx is-agentic yourdomain.com` or [is-agentic.com](https://is-agentic.com) | 100+ checks; Essential checks carry most of the score; Recommended checks activate only when evidence shows you have that surface (API, MCP server, commerce); not-applicable checks are excluded, not failed; includes an observed agent journey showing where a real agent hit friction || **Frase Agent Readiness Checker** | [frase.io/tools/agent-readiness](https://www.frase.io/tools/agent-readiness) | Access / Discovery / Parseability triad; 80+ = agents can reliably use the site, 60–79 = solid with gaps, <60 = real access problems |
references/agent-readiness.md:12In the instructionsOpen original file
Run one before and after any agent-readiness work — the score is a shareable artifact and the failed checks are your worklist. (Both are vendor tools with a product behind them; the *checks* are the value, not the pitch.)
Medium risk

The Skill recommends a WordPress plugin that is still awaiting directory approval

Source references: 2
What we found

The Skill directs users to a plugin download in a blog post and explicitly says wp.org approval is pending. No plugin source or verifiable build is supplied here, so its claimed read-only behavior cannot be confirmed by this audit.

Why this matters

WordPress plugins execute on the server and commonly have access to site content, the database, and configuration. A compromised or misrepresented plugin could change pages, disclose data, or take control of the site.

The file presents the plugin as an actionable way to ship OKF and directs users to a blog-hosted download while stating that wp.org approval is still pending. The supplied evidence contains no plugin source, pinned version, or checksum; “read-only” is only a documentation claim and cannot be verified here. If installed, plugin code would run with WordPress/PHP access and could reach site data or settings. Users can wait for directory review or request auditable source, a fixed version, and a checksum.

references/okf.md:70In the instructionsOpen original file
### 2. WordPress plugin (pending wp.org approval)Suganthan's plugin (free, GPL, awaiting wp.org approval at time of writing) installs in a minute, serves the bundle at `/okf/`, and rebuilds on every publish or edit so it stays in sync. Direct download link is in [his blog post](https://suganthan.com/blog/open-knowledge-format/). Requires WordPress 6.0+ and PHP 7.4+. Read-only — never edits posts or settings.
Show 1 other places
references/okf.md:62In the instructionsOpen original file
## How to ship oneThree options, ordered by how much effort they take:### 1. Suganthan's free web tool (recommended for most sites)
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

The third-party OKF generator receives a site entry point and crawls up to 100 pages

Source references: 2
What we found

The recommended workflow asks users to paste a URL or sitemap into an external website, which then crawls pages and creates a downloadable bundle. A sitemap may expose obscure but still reachable URLs.

Why this matters

The provider learns the submitted domain, URL inventory, and crawled page contents. If the sitemap includes staging, customer-specific, or accidentally public locations, that material may be additionally disclosed and retained.

The recommended option asks the user to submit a site URL or sitemap to a third-party web tool and explicitly says it crawls up to 100 pages. If the sitemap lists publicly reachable but obscure pages, the service may request those pages while generating the bundle; the evidence gives no retention, access-control, or deletion policy. This risk arises only if the user chooses the external service. Users can provide a restricted sitemap, verify the service's privacy terms, or use a locally auditable generation method.

references/okf.md:66In the instructionsOpen original file
### 1. Suganthan's free web tool (recommended for most sites)[suganthan.com/okf-generator](https://suganthan.com/okf-generator/) — paste a URL or sitemap, crawls up to 100 pages, returns a downloadable bundle. Also draws the resulting page graph so you can spot disconnected pages before publishing.
Show 1 other places
references/okf.md:64In the instructionsOpen original file
Three options, ordered by how much effort they take:### 1. Suganthan's free web tool (recommended for most sites)[suganthan.com/okf-generator](https://suganthan.com/okf-generator/) — paste a URL or sitemap, crawls up to 100 pages, returns a downloadable bundle. Also draws the resulting page graph so you can spot disconnected pages before publishing.
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.Risks found: 2
Medium risk

Blanket AI-crawler access expands content access and may permit training use

Source references: 3
What we found

The reference provides an `Allow: /` configuration for multiple bots and ultimately recommends allowing all AI bots. It also acknowledges that some bots serve both training and search and that users have limited ability to allow citation while refusing training.

Why this matters

After implementation, these bots can crawl every public path, and content may be used for training or other processing the user did not intend. Any accidentally public page protected only by obscurity also becomes easier to discover.

The reference supplies one `Allow: /` rule for several bots and later recommends allowing all AI bots. It also acknowledges that some bots serve both training and search and that this setup cannot separate citation from training for GPTBot. Copying it therefore broadens automated access across the site and may exceed a user's intent to permit citation only. Users should make a bot-by-bot decision based on current platform purposes and their content-licensing policy rather than apply the blanket rule.

references/platform-ranking-factors.md:120In the instructionsOpen original file
```User-agent: GPTBot           # OpenAI — powers ChatGPT searchUser-agent: ChatGPT-User     # ChatGPT browsing modeUser-agent: PerplexityBot    # Perplexity AI searchUser-agent: ClaudeBot        # Anthropic ClaudeUser-agent: anthropic-ai     # Anthropic Claude (alternate)User-agent: Google-Extended   # Google Gemini and AI OverviewsUser-agent: Bingbot          # Microsoft Copilot (via Bing)Allow: /```
Show 2 other places
references/platform-ranking-factors.md:131In the instructionsOpen original file
**Training vs. search:** Some AI bots are used for both model training and search citation. If you want to be cited but don't want your content used for training, your options are limited — GPTBot handles both for OpenAI. However, you can safely block **CCBot** (Common Crawl) without affecting any AI search citations, since it's only used for training dataset collection.
references/platform-ranking-factors.md:147In the instructionsOpen original file
**Actions that help everywhere:**1. Allow all AI bots in robots.txt2. Implement schema markup (FAQPage, Article, Organization at minimum)3. Include statistics with named sources in your content
Low risk

The install command does not pin a dependency version

Source references: 3
What we found

The installation command does not specify dependency versions. The same command may download different code later, so what you install can differ from what was checked.

Why this matters

A later install may download different code even though the command and this report have not changed.

The main Skill directs the user to this checker, and the reference says to run it before and after the work. `npx is-agentic` does not pin a package version; if no trusted local copy exists, npx may fetch and execute the version current at that time, so later runs can execute different code. No version, hash, or pre-execution review step is provided. A user can ask for a pinned, verifiable version or use the web-based checker instead.

SKILL.md:281In the instructionsOpen original file
**Audit this layer first**: [references/agent-readiness.md](references/agent-readiness.md) — the access/discovery/parseability checklist, free scoring tools (`npx is-agentic`, Frase's checker), Markdown content negotiation + `Link` headers, `llms-full.txt`, and the emerging agent-*actionable* layer (WebMCP).
Show 2 other places
references/agent-readiness.md:9In the instructionsOpen original file
|---|---|---|| **Is Agentic** (Vercel + Ora) | `npx is-agentic yourdomain.com` or [is-agentic.com](https://is-agentic.com) | 100+ checks; Essential checks carry most of the score; Recommended checks activate only when evidence shows you have that surface (API, MCP server, commerce); not-applicable checks are excluded, not failed; includes an observed agent journey showing where a real agent hit friction || **Frase Agent Readiness Checker** | [frase.io/tools/agent-readiness](https://www.frase.io/tools/agent-readiness) | Access / Discovery / Parseability triad; 80+ = agents can reliably use the site, 60–79 = solid with gaps, <60 = real access problems |
references/agent-readiness.md:12In the instructionsOpen original file
Run one before and after any agent-readiness work — the score is a shareable artifact and the failed checks are your worklist. (Both are vendor tools with a product behind them; the *checks* are the value, not the pitch.)
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

8 instruction sections

This Skill provides AI-search optimization guidance intended to increase the chance that Google AI Overviews, ChatGPT, Perplexity, and similar systems retrieve and cite a site. It first asks about current visibility, content structure, business goals, and competitors.

View source
SKILL.md:10In the instructionsOpen original file
You are an expert in AI search optimization — the practice of making content discoverable, extractable, and citable by AI systems including Google AI Overviews, ChatGPT, Perplexity, Claude, Gemini, and Copilot. Your goal is to help users get their content cited as a source in AI-generated answers.
SKILL.md:17In the instructionsOpen original file
Gather this context (ask if not provided):

Before starting, it reads a product-marketing context file from the project and uses that information in later recommendations. This may include positioning, competitors, and business goals, but the supplied source does not instruct the agent to transmit that file externally.

View source
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.

Its main outputs are audits and content recommendations covering multiple platforms, extractability, robots.txt, structured data, and repeated-query monitoring of citation rates.

View source
SKILL.md:116In the instructionsOpen original file
### Step 1: Check AI Answers for Your Key QueriesTest 10-20 of your most important queries across platforms:
SKILL.md:141In the instructionsOpen original file
### Step 3: Content Extractability CheckFor each priority page, verify:| Check | Pass/Fail ||-------|-----------|| Clear definition in first paragraph? | || Self-contained answer blocks (work without surrounding context)? | || Statistics with sources cited? | || Comparison tables for "[X] vs [Y]" queries? | || FAQ section with natural-language questions? | || Schema markup (FAQ, HowTo, Article, Product)? | || Expert attribution (author name, credentials)? | || Recently updated (within 6 months)? | || Heading structure matches query patterns? | || AI bots allowed in robots.txt? | |
SKILL.md:412In the instructionsOpen original file
AI answers are **non-deterministic** — one run is an anecdote, not a measurement. Run each query 3–5 times per platform and track the mention *rate* with its sample size ("cited 3/5, n=5"), comparing rates over time rather than single runs. Full rigor checklist in [references/format-volatility.md](references/format-volatility.md).

The supplied Skill contains no script that automatically changes the site or deletes files; its implementation is primarily guidance, templates, and external-tool recommendations. Some recommendations create the network, code-execution, and access-control risks listed below if the user follows them.

View source
SKILL.md:174In the instructionsOpen original file
## Optimization Strategy### The Three Pillars```1. Structure (make it extractable)2. Authority (make it citable)3. Presence (be where AI looks)```
SKILL.md:457In the instructionsOpen original file
## Tool IntegrationsFor implementation, see the [tools registry](../../tools/REGISTRY.md).| Tool | Use For ||------|---------|| `semrush` | AI Overview tracking, keyword research, content gap analysis || `ahrefs` | Backlink analysis, content explorer, AI Overview data || `gsc` | Search Console performance data, query tracking || `ga4` | Referral traffic from AI sources |
Start here · InstructionsSKILL.md
ai-seo
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 5 more sections are available in the original file.

File reference map

References: 16
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records10 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/agent-readiness.mdFull text included
  • references/citations-vs-recommendations.mdFull text included
  • references/content-patterns.mdFull text included
  • references/content-types.mdFull text included
  • references/format-volatility.mdFull text included
  • references/okf.mdFull text included
  • references/platform-ranking-factors.mdFull text included
  • references/youtube-ai-citations.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/agent-readiness.mdSupporting file
  • references/citations-vs-recommendations.mdSupporting file
  • references/content-patterns.mdSupporting file
  • references/content-types.mdSupporting file
  • references/format-volatility.mdSupporting file
  • references/okf.mdSupporting file
  • references/platform-ranking-factors.mdSupporting file
  • references/youtube-ai-citations.mdSupporting file

Operations mentioned in code and instructions

Connect to websites
SKILL.md:73In the instructionsOpen original file
**Google's position** ([AI features optimization guide](https://developers.google.com/search/docs/fundamentals/ai-optimization-guide)):> "The best practices for SEO continue to be relevant because our generative AI features on Google Search are rooted in our core Search ranking and quality systems."
SKILL.md:319In the instructionsOpen original file
**`/llms.txt`** — Context file for AI systems (see [llmstxt.org](https://llmstxt.org))
SKILL.md:325In the instructionsOpen original file
Google [introduced OKF](https://cloud.google.com/blog/products/data-analytics/how-the-open-knowledge-format-can-improve-data-sharing) in June 2026 — a markdown spec for representing site content as a directory of cross-linked files with YAML frontmatter, agent-readable without scraping. Built primarily for data-team catalog metadata; the site-readable-by-agents repurposing was popularized by Suganthan Mohanadasan. No confirmed AI-search ranking signal today — treat it as protocol-layer registration like early schema.org. **For the full breakdown, implementation paths (free generator, WordPress plugin, by-hand), hosting guidance, and when to skip, see [references/okf.md](references/okf.md).**
Read files
SKILL.md:85In the instructionsOpen original file
- They actively reward extractable structure — passages, FAQs, comparison tables, definition blocks- They parse `llms.txt`, structured pricing pages, and machine-readable files when present- They cite third-party sources (Reddit, Wikipedia, review sites) more heavily than top-ranked pages
SKILL.md:91In the instructionsOpen original file
- For Google AI Overviews / AI Mode specifically: optimize for people and core Search, full stop. Strong E-E-A-T, original information, semantic HTML, clean indexability.- For ChatGPT/Claude/Perplexity: layer on the extractable structure + llms.txt + machine-readable files.
SKILL.md:273In the instructionsOpen original file
### Machine-Readable Files for AI Agents
Read keys or account settings
SKILL.md:153In the instructionsOpen original file
| Schema markup (FAQ, HowTo, Article, Product)? | || Expert attribution (author name, credentials)? | || Recently updated (within 6 months)? | |
SKILL.md:233In the instructionsOpen original file
**Expert attribution** (+25-30% citation boost)- Named authors with credentials- Expert quotes with titles and organizations
references/content-patterns.md:246In the instructionsOpen original file
- Cite peer-reviewed studies with publication details- Include expert credentials (MD, RN, etc.)- Note study limitations and context
Install extra software packages
SKILL.md:281In the instructionsOpen original file
**Audit this layer first**: [references/agent-readiness.md](references/agent-readiness.md) — the access/discovery/parseability checklist, free scoring tools (`npx is-agentic`, Frase's checker), Markdown content negotiation + `Link` headers, `llms-full.txt`, and the emerging agent-*actionable* layer (WebMCP).
evals/evals.json:119In the instructionsOpen original file
      "prompt": "Our content is well-written and we have schema markup, but AI assistants never seem to use our site. Someone said our site might not be 'agent-ready.' We also put most of our AI-visibility effort into Reddit this year since       "expected_output": "Should load references/agent-readiness.md and address both halves. (1) Agent readiness: recommend running a free scoring tool (npx is-agentic and/or Frase's Agent Readiness Checker) and walk the access/discovery/parseability triad — core content must be in the initial HTML without JavaScript execution, no bot challenge/firewall blocking AI crawlers, robots.txt with an explicit AI-crawler stance, clean sitemap, llms.txt (+llms-full.txt as bonus), structured data, and a Markdown representation via content negotiation (Accept: text/markdown at the same canonical URL) or a Link header. May mention WebMCP as the emerging agent-actionable layer, labeled emerging. (2) Reddit concentration: flag citation-source volatility — ChatGPT's Aug 2026 retrieval changes nearly wiped Reddit as a source (practitioner-reported), so single-surface concentration is fragile; recommend the portfolio approach across third-party surfaces plus owned-site fundamentals (which dominate Gemini citations), and verifying any citation-share stat against their own monitoring before betting budget.",      "assertions": [
references/agent-readiness.md:9In the instructionsOpen original file
|---|---|---|| **Is Agentic** (Vercel + Ora) | `npx is-agentic yourdomain.com` or [is-agentic.com](https://is-agentic.com) | 100+ checks; Essential checks carry most of the score; Recommended checks activate only when evidence shows you have that surface (API, MCP server, commerce); not-applicable checks are excluded, not failed; includes an observed agent journey showing where a real agent hit friction || **Frase Agent Readiness Checker** | [frase.io/tools/agent-readiness](https://www.frase.io/tools/agent-readiness) | Access / Discovery / Parseability triad; 80+ = agents can reliably use the site, 60–79 = solid with gaps, <60 = real access 
Lines read
1,549
File checksum (to compare versions)
424cd2d4dc76476121e046655d70eb9024bfff37ab0d549a6b4e6af31b6add16