Skip to content
Report library
Purpose / Data analysis

Programmatic Seo Skill Security Audit

What the author says it does (original text)

When the user wants to create SEO-driven pages at scale using templates and data. Also use when the user mentions "programmatic SEO," "template pages," "pages at scale," "directory pages," "location pages," "[keyword] + [city] pages," "comparison pages," "integration pages," "building many pages for SEO," "pSEO," "generate 100 pages," "data-driven pages," or "templated landing pages." Use this whe

Independent security check

Security risks found

Files checked
3
Risks found
2
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 2
Medium risk

Automatically reads project marketing files, potentially bringing unnecessary confidential business information into the AI session

Source references: 1
What we found

When a file exists at one of the named paths, the Skill requires reading it first without task-specific user confirmation or a limit to SEO-relevant sections. Such files may contain non-public positioning, customer, conversion, or competitive information.

Why this matters

The contents may enter model context, conversation records, or later outputs. Confidential strategy or customer information could therefore be exposed beyond what the user expected from an SEO-planning request.

The live instruction requires reading a product-marketing file, if present at one of the named paths, before asking questions. If that file contains unpublished customer, positioning, competitive, or conversion information, it may enter the model context even when the full file is unnecessary for the SEO task. A user can ask the author to require confirmation and read only explicitly relevant sections, or restrict access to these paths.

SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
Medium risk

Prioritizes user-derived SEO data without requiring privacy, consent, or aggregation checks

Source references: 2
What we found

The Skill ranks product-derived data “from your users” and community-generated data above licensed or public sources, then asks what data will populate each page. It does not pair this guidance with checks for personal information, user consent, anonymization, or publication rights.

Why this matters

If a team follows this priority using raw customer behavior, user profiles, or community submissions, public pages could inadvertently disclose personal information or customer secrets, or reuse data beyond its original purpose.

The Skill explicitly ranks product data “from your users” and community-generated data as preferred content sources, then asks what data will populate each page and where it comes from. The visible instructions do not require checks for personal information, consent, anonymization, or publication rights. If an agent consequently uses raw user data on public SEO pages, personal or customer information could be exposed or used beyond its authorization. Users can require publication rights, aggregation/anonymization, and privacy review before use.

SKILL.md:43In the instructionsOpen original file
### 2. Proprietary Data WinsHierarchy of data defensibility:1. Proprietary (you created it)2. Product-derived (from your users)3. User-generated (your community)4. Licensed (exclusive access)5. Public (anyone can use—weakest)
Show 1 other places
SKILL.md:122In the instructionsOpen original file
### 2. Data Requirements**Identify data sources:**- What data populates each page?- Is it first-party, scraped, licensed, public?- How is it updated?
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

8 instruction sections

This Skill is a planning guide for researching keyword patterns, choosing page types, and designing SEO pages at scale; the supplied files contain no installation commands, executable scripts, or instructions that directly publish pages.

View source
SKILL.md:108In the instructionsOpen original file
## Implementation Framework### 1. Keyword Pattern Research
SKILL.md:207In the instructionsOpen original file
## Output Format### Strategy Document- Opportunity analysis- Implementation plan- Content guidelines### Page Template- URL structure- Title/meta templates- Content outline- Schema markup

The guide emphasizes unique value on every page and explicitly rejects doorway pages, keyword stuffing, and duplicate content.

View source
SKILL.md:38In the instructionsOpen original file
### 1. Unique Value Per Page- Every page must provide value specific to that page- Not just swapped variables in a template- Maximize unique content—the more differentiated, the better
SKILL.md:62In the instructionsOpen original file
### 6. Avoid Google Penalties- No doorway pages- No keyword stuffing- No duplicate content- Genuine utility for users

Before planning, the Skill looks for and reads a product-marketing context file in the project, then asks only for information not already covered.

View source
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
Start here · InstructionsSKILL.md
programmatic-seo
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 2 more sections are available in the original file.

File reference map

References: 1
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records3 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/playbooks.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/playbooks.mdSupporting file

Operations mentioned in code and instructions

Connect to websites
evals/evals.json:54In the instructionsOpen original file
      "prompt": "We built 500 programmatic pages but Google isn't indexing most of them. Only 80 are in the index. What's going wrong?",      "expected_output": "Should diagnose the indexation problem. Should apply the quality checks and indexation strategy guidance. Should investigate: thin content (are pages providing unique value or just template + keyword?), crawl budget (500 pages may be fine but depends on site authority), internal linking (are the pages discoverable?), XML sitemap inclusion, duplicate/near-duplicate content issues. Should recommend specific fixes: improve content uniqueness, strengthen internal linking, submit sitemap, check robots.txt, use Search Console for indexation requests. Should warn that Google may choose not to index thin pages regardless.",      "assertions": [
Lines read
643
File checksum (to compare versions)
522bbe09cbe1710468fe4edbc10ded9758e2554243570502c101fab3d2955855