seo-scorecard

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes git log to analyze commit history for attributing SEO changes to specific ship dates. It also uses pnpm format to ensure the generated markdown report adheres to project styling standards.
  • [EXTERNAL_DOWNLOADS]: Fetches live content from the site's CMS and public web pages to verify that SEO optimizations are correctly deployed and to check visibility in AI-based search tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data which could contain malicious instructions designed to influence the agent's reporting or behavior.
  • Ingestion points: Processes Google Search Console (GSC) CSV exports, GA4 report data, live CMS content, and external web page content.
  • Boundary markers: Absent; there are no instructions to wrap or delimit external data to prevent the agent from following embedded instructions.
  • Capability inventory: File system read/write/delete operations, Git command execution, and network fetching via tool calls.
  • Sanitization: Absent; the agent is directed to read and compute statistics directly from the raw external files and site content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 12:08 PM
Security Audit — agent-trust-hub — seo-scorecard