Surfer SEO SERP Analyzer
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npxto install from theagentskillexchange/skillsregistry. This is documented as the author's own distribution channel and is consistent with the skill's provenance. - [PROMPT_INJECTION]: The skill processes third-party SERP data and NLP entity recommendations from the Surfer SEO API, creating a surface for indirect prompt injection. * Ingestion points: Data retrieved from Surfer SEO Content Editor and Audit API endpoints. * Boundary markers: The documentation does not describe the use of markers or delimiters to isolate untrusted data. * Capability inventory: Retrieves word count benchmarks, heading patterns, and keyword clusters to generate content briefs. * Sanitization: No explicit sanitization or validation of the external API responses is mentioned.
Audit Metadata