r16-voltagent-seo-content-marketing-agent-skills

Warn

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to clone a repository from an unverified GitHub account (Gravityaespot). Downloading and installing extensions or code from non-trusted third-party sources poses a risk as the code has not been audited for malicious behavior.
  • [COMMAND_EXECUTION]: The installation guide involves manual shell commands to copy third-party files into the agent's sensitive local configuration directory (~/.claude/skills/).
  • [PROMPT_INJECTION]: The skill possesses a significant surface for indirect prompt injection attacks due to its core functionality of auditing external content.
  • Ingestion points: Commands like /content-audit, /technical-seo, and /competitor-gap (SKILL.md) ingest and process data directly from external URLs provided by the user or discovered during crawls.
  • Boundary markers: There are no documented delimiters or "ignore embedded instructions" warnings to prevent the agent from following malicious commands found on audited sites.
  • Capability inventory: The skill is designed to perform network crawling and file-system operations (writing reports in various formats).
  • Sanitization: The instructions do not describe any sanitization or validation of the external content before it is interpolated into the agent's context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 17, 2026, 06:29 PM
Security Audit — agent-trust-hub — r16-voltagent-seo-content-marketing-agent-skills