88OUT OF 100
Likely safeLikely safeStatic read

AgriciDaniel/claude-seo

Claude SEO is a well-documented, open-source plugin for Claude Code. The repository exhibits high transparency, with all network-based installation patterns clearly disclosed in the README and consistent with the project's stated purpose as an AI-agent skill. No malicious behavior, obfuscation, or unauthorized credential access was observed in the static analysis. While the use of curl-to-bash installation patterns requires standard user caution, these are fully aligned with the project's documented setup intent.

Repository size
6909 KB
Packages
0
Stars
17561
Created
423 days ago
Reputation signals
AgriciDaniel avatar
Agrici.Daniel
@AgriciDaniel
Account age1 yr 1 mo
Public repos71
Forks2.6k
Community sentiment95

High community engagement

Code & behavior signals
Installation-time network fetch
LowBehavior

The project uses curl-to-bash installation scripts. This is a common pattern for CLI tools but carries inherent supply-chain risks. The behavior is fully disclosed in the README and consistent with the project's intent.

Cross-repo provisioning fetch
LowCode

Extension scripts reference the main installation script via raw.githubusercontent.com. This is a standard modular design for this toolset and is verified as a recognized software-distribution host.

Per-package scoring
Final verdict

No malicious behavior in our static read. The caveats above are worth noting and the owner is not yet long-established. Runtime was not executed in a sandbox on this pass.

What we could not verify
—Full runtime behavior (this repo was not executed in a sandbox on this pass)
—Every conditional and time-triggered branch
—Behavior under real credentials (no sandbox was run on this pass)
End-to-end logs
Clone
›Repository cloned successfully.
›Commit hash e77e783e38eeb738424eb72117abbd2dacdd88af verified.
Static scan
›No obfuscation detected.
›No hardcoded credentials found.
›No unauthorized install hooks identified.
Reputation
›Owner is highly established with significant public contributions.
›High star count indicates strong community trust.
Read
›README clearly documents installation via shell scripts.
›Flagged regions match documented installation patterns exactly.
›No undisclosed network activity found.
Score
›Score computed by formula: 88/100 (deterministic, code-driven)
›-6 [code] network: Code has outbound network capability (fetch / child_process / hardcoded IP URL).
›-6 [code] model_findings: 2 code/behavior finding(s) reported by the read model.
›+8 [reputation] established_owner: Owner account is established (older than a year with multiple public repos).
›+6 [reputation] many_stars: Strong community signal (17,561 stars).
›+4 [reputation] good_sentiment: Positive community sentiment (95/100).
Auto-published at clauderabbit.in/AgriciDaniel/claude-seo · re-checked when the repo changes