seo-audit

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external content (website HTML) using tools like web_fetch or curl. This introduces an inherent surface for indirect prompt injection where malicious instructions embedded in a target website's source code could attempt to influence the agent's behavior.
  • Ingestion points: Processes external website content via URL fetching (SKILL.md).
  • Boundary markers: The instructions do not explicitly define boundary markers or 'ignore' commands for content fetched from external URLs.
  • Capability inventory: The skill primarily performs analysis and report generation; however, the agent platform using this skill may possess capabilities like file system access or terminal execution.
  • Sanitization: No specific sanitization or filtering of fetched HTML content is mentioned before the agent processes it for the audit report.
  • [EXTERNAL_DOWNLOADS]: The skill references several well-known and trusted SEO diagnostic services and documentation sources, including Google Search Console, Google Rich Results Test, and PageSpeed Insights. These references are standard for the tool's intended purpose and target established, reputable domains.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 08:59 AM
Security Audit — agent-trust-hub — seo-audit