seo
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches SEO metrics and mapping data from several well-known third-party services, including Google, Bing, Moz, DataForSEO, Geoapify, and OpenStreetMap (SKILL.md, references/free-backlink-sources.md).
- [COMMAND_EXECUTION]: The skill uses a custom launcher utility (
claude-seo) to execute a suite of bundled Python scripts and Node.js utilities (Lighthouse) for performance and technical analysis (SKILL.md, references/cwv-thresholds.md). - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill is designed to crawl and analyze the HTML content of arbitrary websites provided by users during audits and page analysis (SKILL.md).
- Boundary markers: The instructions do not specify explicit delimiters or "ignore" instructions for the ingested content, though they mention a synthesis framework that processes findings through multiple thinking phases.
- Capability inventory: The skill possesses network communication capabilities via curl and API integrations, and it can execute local scripts (SKILL.md, references/cwv-thresholds.md).
- Sanitization: There are no documented procedures for sanitizing or escaping the content retrieved from external URLs before it is processed by the agent.
Audit Metadata