seo-dataforseo
Warn
Audited by Snyk on Feb 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill calls the DataForSEO APIs (e.g., scripts/api/serp.py — get_google_serp/get_youtube_serp/get_google_news_serp/get_google_images_serp, scripts/api/trends.py — get_trending_now/get_trends_explore, and scripts/api/keywords_data.py — get_keywords_for_site) to fetch public Google/YouTube/News/Trends/SERP results and competitor site data, which are untrusted, user-generated or third‑party web content that the agent reads and summarizes.
Audit Metadata