seo-audit
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches an installation script for the Bright Data CLI from
https://cli.brightdata.com/install.sh, which is an official resource provided by the author. - [REMOTE_CODE_EXECUTION]: The CLI tool is installed by piping a remote script directly to the bash shell (
curl -fsSL ... | bash). This behavior is restricted to the vendor's own verified infrastructure. - [INDIRECT_PROMPT_INJECTION]: The skill ingests HTML content from arbitrary external websites to perform audits, which could expose the agent to malicious data designed to influence its reasoning or output.
- Ingestion points: Data is retrieved from user-specified URLs and sitemaps using
bdata scrapeas described inreferences/bdata-recipes.md. - Boundary markers: The agent follows defined extraction recipes which provide structural isolation, though these do not fully eliminate injection risks.
- Capability inventory: The agent has access to web scraping and shell command execution.
- Sanitization: Processing is performed using standard utilities like
grep,jq, andpython3to extract specific SEO elements. - [DYNAMIC_EXECUTION]: The skill executes a Python script provided via a heredoc in
references/bdata-recipes.md(R-07) to extract JSON-LD schema markup from rendered HTML. - [COMMAND_EXECUTION]: The audit workflow utilizes standard command-line tools including
grep,sed,awk, andjqfor data analysis.
Recommendations
- HIGH: Downloads and executes remote code from: https://cli.brightdata.com/install.sh - DO NOT USE without thorough review
Audit Metadata