seo-audit
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from URLs or text input to perform its audit, creating a surface for instructions embedded in that data to influence agent behavior.
- Ingestion points: Untrusted content is ingested via the
contentparameter (which can be a URL or raw text) and thecompetitor_urlslist as defined in the Input Schema and workflow steps. - Boundary markers: The instructions lack specific boundary markers or delimiters to isolate untrusted external content from the skill's logic.
- Capability inventory: The agent uses text generation and is instructed to use
web_searchorweb_browsetools to fetch competitor data. - Sanitization: There are no instructions for sanitizing, escaping, or filtering the external content before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill is designed to fetch and analyze external content from user-specified URLs and competitor websites.
- Evidence: The Input Schema allows for URLs in the
contentfield and a list ofcompetitor_urls. The workflow explicitly mentions fetching content if a URL is provided and usingweb_search/web_browsefor competitive comparisons.
Audit Metadata