seo-forge

Warn

Audited by Socket on Mar 21, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/seo-research.sh

The script functions as a straightforward DataForSEO integration wrapper with a clear fallback path when credentials are absent. It performs expected data collection (SERP, PAA, volume, related keywords) and supports JSON output for automation. Security concerns are limited to credential handling in the execution context (process listings and logs) and potential JSON payload integrity issues if the keyword contains special characters. Overall, the approach is reasonable for its purpose but would benefit from input sanitization, explicit error handling, and safer credential handling.

Confidence: 54%Severity: 60%
AnomalyLOW
SKILL.md

SUSPICIOUS. The core SEO-writing purpose matches most capabilities, and the named external APIs are official and proportionate. However, the skill executes unseen scripts, processes untrusted web content while writing files, and extends trust to an unreviewed companion skill, so the overall risk is medium rather than benign.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Mar 21, 2026, 07:28 PM
Package URL
pkg:socket/skills-sh/TheMattBerman%2Fseo-kit%2Fseo-forge%2F@e0e58c91b0e6f2ab110e78c66920ce9da83caf69