seo-content-writer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of user-provided content briefs and competitor URLs during its requirement-gathering phase in
SKILL.md. - Ingestion points: Step 1 (Gather Requirements) processes external topics and URLs.
- Boundary markers: Absent; the skill relies on the agent's internal instruction-following logic.
- Capability inventory: Limited to text generation and writing files to the local
memory/directory. - Sanitization: Absent; content is used directly for generation. This finding represents a standard attack surface for a writing-focused skill and is considered safe given the skill's intended purpose and limited capabilities.
- [DATA_EXFILTRATION]: There is no evidence of unauthorized network transmission. The skill includes instructions to save dated summaries of generated content to the local
memory/content/directory. This is a standard persistence mechanism used to maintain session history and does not involve sending data to external domains. - [SAFE]: A thorough review of the skill's instructions, templates, and reference materials (including
references/instructions-detail.mdandreferences/seo-writing-checklist.md) confirms that it does not contain any obfuscated content, remote code execution triggers, or persistence mechanisms. The skill operates entirely within its stated scope of SEO content creation.
Audit Metadata