skills/celeroncoder/skills/seo-audit/Gen Agent Trust Hub

seo-audit

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze content from external websites, which are untrusted sources of data.\n- Ingestion points: The agent retrieves HTML, metadata, and structured data using tools such as web_fetch, curl, and the browser tool as described in SKILL.md.\n- Boundary markers: The prompt instructions lack explicit delimitation or clear directives to the agent to disregard potential instructions embedded within the fetched content.\n- Capability inventory: The agent has capabilities to fetch web content, read local product marketing context files (.agents/product-marketing-context.md), and generate audit reports.\n- Sanitization: No specific sanitization, filtering, or validation logic is defined for the external data before it is processed by the agent.\n- [DATA_EXFILTRATION]: The skill conducts network operations to external, non-whitelisted domains which, when combined with access to local sensitive context files, presents a potential exposure risk.\n- Evidence: The instructions guide the agent to use web_fetch and curl to access arbitrary URLs to check for site architecture, robots.txt, and page content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:57 PM
Security Audit — agent-trust-hub — seo-audit