seo-programmatic

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines processes for ingesting data from external files, APIs, and databases, which presents a surface for indirect prompt injection attacks. If the ingested data contains instructions designed to override the agent's behavior, the agent may follow them without explicit boundaries.
  • Ingestion points: The 'Data Source Assessment' section of SKILL.md identifies CSV/JSON files, API endpoints, and database queries as primary inputs.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are specified for the processing of these data sources.
  • Capability inventory: The skill instructs the agent to analyze and plan based on external data, which may involve reading file contents or API responses.
  • Sanitization: The skill does not provide instructions for sanitizing, validating, or escaping content retrieved from untrusted external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:56 PM
Security Audit — agent-trust-hub — seo-programmatic