algo-seo-technical

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes performance data from external sources like the Google CrUX API and Lighthouse reports, creating an attack surface for indirect prompt injection. * Ingestion points: Field data and metrics from the CrUX API (references/crux-monitoring.md). * Boundary markers: The instructions lack explicit delimitation to separate ingested data from agent commands. * Capability inventory: The skill performs network requests to retrieve performance metrics. * Sanitization: No explicit validation or sanitization of API data is performed.
  • [SAFE]: The skill fetches performance telemetry from a well-known service (Google APIs) which is a standard operational requirement for SEO auditing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:05 PM
Security Audit — agent-trust-hub — algo-seo-technical