skills/davidlangat/skills/seo/Gen Agent Trust Hub

seo

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to audit and process external websites, URLs, and codebases. This creates a surface for indirect prompt injection where malicious instructions could be embedded in technical SEO metadata (like meta tags or robots.txt) on a target site. However, the skill's instructions are highly specific to SEO analysis, which significantly limits the potential impact.
  • Ingestion points: Processes external URLs, website content, and code repositories in SKILL.md sections 1, 9, 10, 18, and 19.
  • Boundary markers: The instructions do not explicitly mandate the use of delimiters when the agent processes external text.
  • Capability inventory: The skill is authorized to perform audits and suggest/implement code changes (Next.js metadata, JSON-LD) based on the ingested data.
  • Sanitization: No specific sanitization or filtering of external content is mentioned beyond checking for SEO relevance.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 07:37 PM
Security Audit — agent-trust-hub — seo