seo-content-marketing-claude-skill-suite

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation instructions provide commands to clone a repository and download a compressed archive from an untrusted GitHub account (JaguarPillage).
  • [PROMPT_INJECTION]: The skill features a significant surface for indirect prompt injection because it is designed to crawl and analyze untrusted content from external websites.
  • Ingestion points: The skill ingests data from external URLs (via audit commands) and local CSV files (via keyword and monitoring commands).
  • Boundary markers: The provided instructions do not include boundary markers or guidance for the agent to ignore potentially malicious instructions embedded in the audited content.
  • Capability inventory: The skill makes network calls to external SEO APIs (Semrush, Ahrefs, Moz, etc.) and performs file system operations to export reports.
  • Sanitization: There is no indication of sanitization or validation performed on the HTML or data retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 08:27 AM
Security Audit — agent-trust-hub — seo-content-marketing-claude-skill-suite