Caveat verdict
citedy-seo-agent
The skill transmits user data (content) to external services (OpenAI's API) for SEO and content marketing purposes. While not directly malicious, it involves sharing potentially sensitive information with third-party services.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Possible prompt injection โ attempts to redefine agent identity
SKILL.md ยท prose ยท downgraded ยท You are now
References webhook/callback URL
SKILL.md ยท code ยท callback_url
Data encoding/decoding
SKILL.md ยท code
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: CITEDY_API_KEY).
network_indata_encoding Is this flag fair?
Thanks โ recorded.