seo-audit
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The scripts
scripts/content_scorer.py,scripts/redirect_checker.py, andscripts/sitemap_analyzer.pyall ingest content from user-provided local files or external URLs. - Boundary markers: The skill does not employ explicit delimiters or instructions to the agent to ignore embedded prompts in the analyzed data.
- Capability inventory: The skill has the capability to read local files and perform network operations (GET and HEAD requests).
- Sanitization: No sanitization of the processed content for prompt injection patterns is evident in the analysis scripts.
- [COMMAND_EXECUTION]: The skill relies on the execution of Python scripts (
content_scorer.py,redirect_checker.py,sitemap_analyzer.py) to perform its primary SEO diagnostic functions. - [DATA_EXFILTRATION]: The scripts
scripts/redirect_checker.pyandscripts/sitemap_analyzer.pyperform network requests to arbitrary URLs. While this is the intended purpose of the skill (auditing sites), this capability could be misused to probe internal network resources (SSRF).
Audit Metadata