seo-visibility-expert

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill performs technical SEO audits and competitor research by fetching content from external websites via WebFetch and WebSearch. This introduces untrusted data into the agent's context, which could contain malicious instructions designed to hijack the agent's logic. The skill has permissions for Bash, Write, and Edit operations, allowing potential exploitation of this surface if the agent obeys instructions embedded in the external content.
  • Ingestion points: Technical SEO audits and competitor analysis using WebFetch and WebSearch.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' rules to separate fetched content from system instructions.
  • Capability inventory: The skill has access to Bash, Write, Edit, Glob, and Grep tools.
  • Sanitization: No explicit sanitization or content validation steps are defined for data retrieved from web sources.
  • [COMMAND_EXECUTION]: The skill is designed to use the Bash tool for technical SEO maintenance tasks such as creating or modifying robots.txt, llms.txt, and sitemap.xml files. While these actions are aligned with the skill's primary purpose, the use of shell commands based on findings from untrusted external web audits requires careful handling to prevent unintended behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — seo-visibility-expert