External SEO services and account access may expose private site and analytics data
Source references: 5The Skill asks whether Search Console or analytics access is available and recommends services such as Google Rich Results Test, PageSpeed Insights, WebPageTest, Ahrefs, and Semrush. If a user submits staging, token-bearing, or otherwise private URLs, or grants broad account access, those services or the agent session may receive page content, URLs, search-performance data, and competitive information.
Unreleased pages, internal URL parameters, traffic, and keyword-performance data could be disclosed. Writable access would also increase the consequences of account mistakes, although the visible instructions do not request account changes.
The Skill does ask whether Search Console/analytics access is available and lists external services including Google, WebPageTest, Ahrefs, and Semrush. However, the visible instructions do not request credentials, broad account permissions, or submission of staging, token-bearing, or otherwise private URLs. The described exposure would arise only if the user or agent separately chooses to send sensitive URLs, pages, or analytics data to those services; the source does not establish that the Skill requires this. A user can limit inputs to minimal read-only or exported audit data and avoid URLs containing access tokens.
This assessment concerns the code and conditions shown, not proof that harm has occurred.3. **Scope** - Full site audit or specific pages? - Technical + on-page, or one focus area? - Access to Search Console / analytics?Show 4 other places
**To accurately check for schema markup, use one of these methods:**1. **Browser tool** — render the page and run: `document.querySelectorAll('script[type="application/ld+json"]')`2. **Google Rich Results Test** — https://search.google.com/test/rich-results3. **Screaming Frog export** — if the client provides one, use it (SF renders JavaScript)**Tools**- PageSpeed Insights- WebPageTest- Chrome DevTools- Search Console Core Web Vitals report**Paid Tools** (if available)- Screaming Frog- Ahrefs / Semrush- Sitebulb- ContentKing**Free Tools**- Google Search Console (essential)- Google PageSpeed Insights- Bing Webmaster Tools- Rich Results Test (**use this for schema validation — it renders JavaScript**)- Mobile-Friendly Test- Schema Validator> **Note on schema detection:** `web_fetch` strips `<script>` tags (including JSON-LD) and cannot detect JS-injected schema. Use the browser tool, Rich Results Test, or Screaming Frog instead — they render JavaScript and capture dynamically-injected markup. See the Schema Markup Detection Limitation section above.**Paid Tools** (if available)- Screaming Frog- Ahrefs / Semrush- Sitebulb