seo-audit
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze content from external websites, which are untrusted sources of data.\n- Ingestion points: The agent retrieves HTML, metadata, and structured data using tools such as
web_fetch,curl, and thebrowsertool as described inSKILL.md.\n- Boundary markers: The prompt instructions lack explicit delimitation or clear directives to the agent to disregard potential instructions embedded within the fetched content.\n- Capability inventory: The agent has capabilities to fetch web content, read local product marketing context files (.agents/product-marketing-context.md), and generate audit reports.\n- Sanitization: No specific sanitization, filtering, or validation logic is defined for the external data before it is processed by the agent.\n- [DATA_EXFILTRATION]: The skill conducts network operations to external, non-whitelisted domains which, when combined with access to local sensitive context files, presents a potential exposure risk.\n- Evidence: The instructions guide the agent to useweb_fetchandcurlto access arbitrary URLs to check for site architecture, robots.txt, and page content.
Audit Metadata