seo-content-brief
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted content from external URLs (including target websites, competitor pages, and sitemaps) to generate research-backed briefs. This architectural pattern creates a surface for indirect prompt injection if the fetched pages contain malicious natural language instructions designed to influence the agent's behavior.
- Ingestion points: Target homepage, URL, and sitemap provided by the user (SKILL.md, steps 1 and 2); top 5 ranking competitor pages for a target keyword (SKILL.md, step 3).
- Boundary markers: The instructions do not define strict delimiters or include 'ignore embedded instructions' directives to distinguish between the skill's operational instructions and the data being analyzed from external sources.
- Capability inventory: The skill possesses significant capabilities including detailed content planning, competitive scoring, internal linking suggestions using site structure, and integration with external SEO tools (DataForSEO and Ahrefs MCP tools) for live data extraction.
- Sanitization: No sanitization, filtering, or validation logic is specified to handle or neutralize potentially malicious instructions embedded in the fetched HTML or content.
Audit Metadata