google-yandex-2gis-local-seo
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and process untrusted data from external business websites and mapping platform profiles (Google Business Profile, Yandex Business, 2GIS) during its evidence collection and audit phases.
- Ingestion points: Site source data (contacts, footer, schema), platform source data (GBP/Yandex/2GIS UI/API exports), and analytics data as described in
SKILL.md(Workflow Step 2). - Boundary markers: The skill lacks explicit prompt delimiters for external content but relies on a strict "Safety Gates" policy to manage the risk.
- Capability inventory: The skill mentions write operations such as
business:kit:write, profile photo uploads, review replies, and sitemap/IndexNow submissions. - Sanitization: No explicit string sanitization is described, but the skill requires explicit user approval before performing any write operations to external platforms or the live site.
- [SAFE]: Credential and Privacy Protection. The skill's instructions explicitly forbid the agent from requesting or storing passwords, cookies, verification codes, private keys, or raw OAuth tokens, ensuring the safety of user credentials.
- [SAFE]: Verified Information Policy. The 'Operating Rule' in
SKILL.mdenforces a strict policy against inventing facts, reviews, or business branches, which prevents the generation of deceptive or harmful SEO content. - [SAFE]: External Resource Review. The
references/skill-candidate-review.mdfile provides a security-conscious evaluation of other local SEO skills, correctly advising against importing external code without thorough manual inspection.
Audit Metadata