Technical issues, weak metadata, and unclear content reduce website visibility. This skill audits those gaps and produces practical SEO and GEO recommendations.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Agent request
Review the Skillstore skill "seo-geo" from https://skillstore.io/skills/resciencelab-seo-geo.md and its manifest at https://skillstore.io/api/skills/resciencelab-seo-geo/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.
Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "seo-geo". Audit https://example.com and prioritize technical fixes.
Expected outcome:
Priority 1: Add a concise meta description to the home page.
Priority 2: Publish a valid sitemap and reference it from robots.txt.
Priority 3: Add verified organization details through structured data.
Using "seo-geo". Research keywords for an accounting platform serving small businesses.
Expected outcome:
The report groups commercial and informational themes, compares demand and difficulty, and recommends a primary topic with supporting article opportunities.
Using "seo-geo". Improve an article for AI answer engines.
Expected outcome:
Place a direct, sourced answer below the main heading.
Add verified statistics and clear attribution near relevant claims.
Organize follow-up questions into concise sections with suitable structured data.
The audit confirms expected outbound requests to selected websites and the fixed DataForSEO API; most alerts are documentation or lexical false positives. The local audit accepts arbitrary URLs without blocking private, loopback, or link-local destinations, creating a high-confidence SSRF risk. No prompt injection or malicious credential handling was found.
The audit passes an unrestricted URL to urllib. A caller can target loopback, link-local, private, or redirected internal HTTP services and expose parsed page data.
The command-line URL flows directly into urllib.request.urlopen without scheme, DNS, private-address, redirect, or response-size validation.
Capability review items (32)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
curl -s "https://example.com/sitemap.xml" | head -30
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
The helper reads a purpose-specific DataForSEO credential from the environment. This is expected authentication behavior, but it is real secret access.
The helper reads a purpose-specific DataForSEO credential from the environment. This is expected authentication behavior, but it is real secret access.
This code performs authenticated HTTPS requests to the fixed DataForSEO API and sends requested SEO query data. The network behavior is expected but real.
This code performs authenticated HTTPS requests to the fixed DataForSEO API and sends requested SEO query data. The network behavior is expected but real.
with urllib.request.urlopen(req, timeout=60) as resp:
This code performs authenticated HTTPS requests to the fixed DataForSEO API and sends requested SEO query data. The network behavior is expected but real.
This code performs authenticated HTTPS requests to the fixed DataForSEO API and sends requested SEO query data. The network behavior is expected but real.
The audit client fetches a user-supplied URL through urllib. This is intended network behavior, but the destination is not restricted to public addresses.
The audit client fetches a user-supplied URL through urllib. This is intended network behavior, but the destination is not restricted to public addresses.
with urllib.request.urlopen(req, timeout=timeout) as resp:
The audit client fetches a user-supplied URL through urllib. This is intended network behavior, but the destination is not restricted to public addresses.
The audit client fetches a user-supplied URL through urllib. This is intended network behavior, but the destination is not restricted to public addresses.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
curl -s "https://example.com/sitemap.xml" | head -50
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
open "https://search.google.com/test/rich-results?url={encoded_url}"
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
open "https://validator.schema.org/?url={encoded_url}"
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
open "https://www.google.com/search?q=site:{domain}"
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
open "https://www.bing.com/search?q=site:{domain}"
This documented workflow issues an outbound request or opens a named search service for the selected website. The behavior is explicit and expected, but requires authorization.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.