seo-audit

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The scripts scripts/content_scorer.py, scripts/redirect_checker.py, and scripts/sitemap_analyzer.py all ingest content from user-provided local files or external URLs.
  • Boundary markers: The skill does not employ explicit delimiters or instructions to the agent to ignore embedded prompts in the analyzed data.
  • Capability inventory: The skill has the capability to read local files and perform network operations (GET and HEAD requests).
  • Sanitization: No sanitization of the processed content for prompt injection patterns is evident in the analysis scripts.
  • [COMMAND_EXECUTION]: The skill relies on the execution of Python scripts (content_scorer.py, redirect_checker.py, sitemap_analyzer.py) to perform its primary SEO diagnostic functions.
  • [DATA_EXFILTRATION]: The scripts scripts/redirect_checker.py and scripts/sitemap_analyzer.py perform network requests to arbitrary URLs. While this is the intended purpose of the skill (auditing sites), this capability could be misused to probe internal network resources (SSRF).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:26 AM
Security Audit — agent-trust-hub — seo-audit