seo-audit
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by design.
- Ingestion points: The skill fetches content from external, user-provided URLs using tools like
web_fetchandcurlas described in SKILL.md. - Boundary markers: There are no specific delimiters or protective instructions provided to the agent to distinguish between legitimate website content and potentially malicious embedded instructions.
- Capability inventory: The agent has the ability to read local project files (e.g., product-marketing-context.md) and generate comprehensive audit reports based on its findings.
- Sanitization: No sanitization or filtering of the fetched web content is performed before it is analyzed by the agent.
- [EXTERNAL_DOWNLOADS]: The instructions reference several well-known and trusted SEO tools, including Google Search Console, PageSpeed Insights, and the Rich Results Test. These references are for legitimate diagnostic purposes and utilize official domains.
Audit Metadata