rank-tracker

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local management script at ${CLAUDE_PLUGIN_ROOT}/scripts/connectors/ledger.py using python3 to record and compare ranking data. This is a functional component of the skill for data handling.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from search engine results and SEO tool exports to monitor visibility features and citation rates, creating a surface for potential indirect injection.
  • Ingestion points: Keyword lists, SERP feature status, and AI citation data from external sources and tool exports.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands in the ingested data.
  • Capability inventory: The skill can write reports to the memory/ directory and execute a local data-processing script.
  • Sanitization: There are no documented methods for sanitizing external metric data before it is formatted into ranking reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 07:29 PM
Security Audit — agent-trust-hub — rank-tracker