rank-tracker
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local management script at
${CLAUDE_PLUGIN_ROOT}/scripts/connectors/ledger.pyusingpython3to record and compare ranking data. This is a functional component of the skill for data handling. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from search engine results and SEO tool exports to monitor visibility features and citation rates, creating a surface for potential indirect injection.
- Ingestion points: Keyword lists, SERP feature status, and AI citation data from external sources and tool exports.
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands in the ingested data.
- Capability inventory: The skill can write reports to the
memory/directory and execute a local data-processing script. - Sanitization: There are no documented methods for sanitizing external metric data before it is formatted into ranking reports.
Audit Metadata