seo-sitemap
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external XML sitemaps and remote URLs. (1) Ingestion points: XML sitemaps and HTTP response data (SKILL.md). (2) Boundary markers: No specific delimiters or safety instructions are defined to separate ingested data from agent instructions. (3) Capability inventory: Network access for URL validation and file system access to the .seo-cache/ directory. (4) Sanitization: No explicit sanitization of sitemap content is mentioned.
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to validate URLs found in sitemaps. Description: In Mode 1, the agent is instructed to verify that all URLs listed in a sitemap return an HTTP 200 status code, which requires connecting to those external domains.
Audit Metadata