seo-profound

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes citation data and brand-mention metrics ingested from external AI platforms such as ChatGPT and Perplexity, which constitutes an indirect prompt injection attack surface. * Ingestion points: Citation metrics and 'top prompt' data from external LLMs. * Boundary markers: No delimiters or specific 'ignore' instructions are present to separate external data from system instructions. * Capability inventory: The skill performs time-series tracking, competitor analysis, and spike alerting across multiple SEO tools. * Sanitization: No evidence of validation or sanitization of the external LLM output is provided.
  • [COMMAND_EXECUTION]: The documentation instructs the execution of local installation scripts ('extensions/profound/install.sh' and 'install.ps1') to configure the extension and environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 11:21 AM
Security Audit — agent-trust-hub — seo-profound