aeo-content-strategy

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md is coherent with its stated purpose and contains no direct malicious code, download-execute chains, credential requests, or obfuscated payloads. Primary risks are operational and privacy-oriented: (1) ingestion of untrusted user-generated content without explicit sanitization creates an indirect prompt-injection and PII-leak risk if an agent processes or republishes raw thread content; (2) the guidance implies scraping/search-engine-based collection without recommending official APIs or rate-limit handling, which can lead to abuse of platform terms and make implementations more likely to use brittle or unsafe scraping code. Overall the file appears benign for intent and capability alignment, but implementers must add sanitization, rate-limit/API guidance, and PII redaction to keep deployments safe.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 01:19 PM
Package URL
pkg:socket/skills-sh/jrr996shujin-png%2Fopenclaw-seo-aeo-skills%2Faeo-content-strategy%2F@d66ca4ec8c02c6809fd7b6dc5e7126b90c20e56e