Surfer SEO SERP Analyzer

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to install from the agentskillexchange/skills registry. This is documented as the author's own distribution channel and is consistent with the skill's provenance.
  • [PROMPT_INJECTION]: The skill processes third-party SERP data and NLP entity recommendations from the Surfer SEO API, creating a surface for indirect prompt injection. * Ingestion points: Data retrieved from Surfer SEO Content Editor and Audit API endpoints. * Boundary markers: The documentation does not describe the use of markers or delimiters to isolate untrusted data. * Capability inventory: Retrieves word count benchmarks, heading patterns, and keyword clusters to generate content briefs. * Sanitization: No explicit sanitization or validation of the external API responses is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 04:36 AM