seo-specialist

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides tools designed to ingest and process external content (Markdown files and CSV keyword lists) for SEO evaluation. While this creates a surface for indirect prompt injection if the processed content contains instructions, it is the primary intended function of the skill.\n
  • Ingestion points: scripts/content_scorer.py reads user-provided Markdown files; scripts/keyword_analyzer.py reads user-provided CSV keyword lists; scripts/serp_simulator.py reads user-provided Markdown files.\n
  • Boundary markers: No explicit delimiters or boundary markers are implemented in the analysis scripts to separate data from instructions.\n
  • Capability inventory: The provided scripts perform read-only operations on local files and output analysis results to the console. They do not possess network access, file-writing permissions, or the ability to execute system commands.\n
  • Sanitization: The scripts do not perform instruction sanitization, as they use regular expressions solely for text pattern matching and statistical scoring rather than executing the content.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 02:59 PM
Security Audit — agent-trust-hub — seo-specialist