seo-content-marketing-claude-skill-suite
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The installation instructions provide commands to clone a repository and download a compressed archive from an untrusted GitHub account (
JaguarPillage). - [PROMPT_INJECTION]: The skill features a significant surface for indirect prompt injection because it is designed to crawl and analyze untrusted content from external websites.
- Ingestion points: The skill ingests data from external URLs (via audit commands) and local CSV files (via keyword and monitoring commands).
- Boundary markers: The provided instructions do not include boundary markers or guidance for the agent to ignore potentially malicious instructions embedded in the audited content.
- Capability inventory: The skill makes network calls to external SEO APIs (Semrush, Ahrefs, Moz, etc.) and performs file system operations to export reports.
- Sanitization: There is no indication of sanitization or validation performed on the HTML or data retrieved from external sources before it is processed by the agent.
Audit Metadata