internal-linking-optimizer

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious code, obfuscation, or unauthorized exfiltration patterns were identified.
  • [DATA_EXPOSURE]: The skill instructions direct the agent to read and write SEO audit data to local project directories such as memory/audits/ and memory/hot-cache.md. This file system interaction is restricted to project-specific paths and is intended for maintaining audit history.
  • [EXTERNAL_DOWNLOADS]: The skill references external URLs on GitHub for its 'Skill Contract', templates, and examples. These resources are hosted within the author's own repository and serve as legitimate configuration and documentation sources.
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection as it processes untrusted data from sitemaps and website content. 1. Ingestion points: website content and sitemaps (SKILL.md). 2. Boundary markers: Absent from the prompt templates. 3. Capability inventory: File-write capabilities to memory/ directories (SKILL.md). 4. Sanitization: No explicit validation or escaping of external content is mentioned. The risk is managed by the skill's use of structured templates for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 08:36 AM