seo-audit
Pass
Audited by Gen Agent Trust Hub on Apr 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of retrieving and analyzing data from external web pages.
- Ingestion points: Untrusted HTML data from external websites is ingested via the referenced
scripts/fetch_page.pyscript inSKILL.md. - Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat crawled content as data rather than instructions.
- Capability inventory: The skill has the capability to execute local scripts (
scripts/fetch_page.py), write multiple files (FULL-AUDIT-REPORT.md,ACTION-PLAN.md), and delegate tasks to several sub-agents. - Sanitization: The skill description contains no mention of sanitizing or validating the crawled HTML content before it is processed by the orchestrator or sub-agents.
Audit Metadata