seo-specialist
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides tools designed to ingest and process external content (Markdown files and CSV keyword lists) for SEO evaluation. While this creates a surface for indirect prompt injection if the processed content contains instructions, it is the primary intended function of the skill.\n
- Ingestion points: scripts/content_scorer.py reads user-provided Markdown files; scripts/keyword_analyzer.py reads user-provided CSV keyword lists; scripts/serp_simulator.py reads user-provided Markdown files.\n
- Boundary markers: No explicit delimiters or boundary markers are implemented in the analysis scripts to separate data from instructions.\n
- Capability inventory: The provided scripts perform read-only operations on local files and output analysis results to the console. They do not possess network access, file-writing permissions, or the ability to execute system commands.\n
- Sanitization: The scripts do not perform instruction sanitization, as they use regular expressions solely for text pattern matching and statistical scoring rather than executing the content.
Audit Metadata