google-yandex-2gis-local-seo

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and process untrusted data from external business websites and mapping platform profiles (Google Business Profile, Yandex Business, 2GIS) during its evidence collection and audit phases.
  • Ingestion points: Site source data (contacts, footer, schema), platform source data (GBP/Yandex/2GIS UI/API exports), and analytics data as described in SKILL.md (Workflow Step 2).
  • Boundary markers: The skill lacks explicit prompt delimiters for external content but relies on a strict "Safety Gates" policy to manage the risk.
  • Capability inventory: The skill mentions write operations such as business:kit:write, profile photo uploads, review replies, and sitemap/IndexNow submissions.
  • Sanitization: No explicit string sanitization is described, but the skill requires explicit user approval before performing any write operations to external platforms or the live site.
  • [SAFE]: Credential and Privacy Protection. The skill's instructions explicitly forbid the agent from requesting or storing passwords, cookies, verification codes, private keys, or raw OAuth tokens, ensuring the safety of user credentials.
  • [SAFE]: Verified Information Policy. The 'Operating Rule' in SKILL.md enforces a strict policy against inventing facts, reviews, or business branches, which prevents the generation of deceptive or harmful SEO content.
  • [SAFE]: External Resource Review. The references/skill-candidate-review.md file provides a security-conscious evaluation of other local SEO skills, correctly advising against importing external code without thorough manual inspection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 11:41 AM
Security Audit — agent-trust-hub — google-yandex-2gis-local-seo