seo-optimization
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation resource for SEO specialists, providing templates for standard web development tasks such as meta tag configuration and JSON-LD generation.
- [DATA_EXPOSURE]: The skill uses clear placeholders like
VERIFICATION_CODEandBING_VERIFICATION_CODEfor site verification settings. It follows security best practices by recommending the use of environment variables and runtime configurations to avoid hardcoding sensitive values. - [UNVERIFIABLE_DEPENDENCIES]: References to external modules such as
@nuxtjs/sitemap,@nuxtjs/robots, and@nuxt/imagetarget well-known, official, or community-standard packages within the web development ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill demonstrates ingesting content from external APIs (e.g.,
fetchArticle(slug)) to populate SEO metadata and JSON-LD scripts. While this represents an attack surface for indirect prompt injection from malicious external data, the pattern follows industry-standard implementation for SEO automation and includes no dangerous autonomous execution capabilities. The risk is assessed as safe given the documentation context. - Ingestion points: External data is fetched in
pages/blog/[slug].vueandapp/blog/[slug]/page.tsx. - Boundary markers: None explicitly shown for data contents.
- Capability inventory: Metadata generation and script tag injection.
- Sanitization: Standard serialization is used for structured data.
Audit Metadata