seo-and-geo

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands like curl within its scripts and documentation to perform technical SEO checks, such as verifying robots.txt files and checking HTTP status codes.
  • [EXTERNAL_DOWNLOADS]: The tool fetches website content and metadata from arbitrary URLs provided by the user or discovered via search for SEO analysis.
  • [DATA_EXFILTRATION]: The skill sends domain and keyword data to the DataForSEO API (api.dataforseo.com) to retrieve SEO metrics. This is the intended purpose of the skill.
  • [PROMPT_INJECTION]: The skill ingests untrusted content from external URLs (Ingestion points: scripts/seo_audit.py, references/backlink-hunter.md) which is then processed by the agent. While no explicit boundary markers are enforced for all inputs, the skill utilizes structured audit templates (Boundary markers). The agent has capabilities for network requests and sending emails (Capability inventory). The documentation recommends manual verification of outreach drafts (Sanitization).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 12:24 PM
Security Audit — agent-trust-hub — seo-and-geo