marketing
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The script
scripts/seo_audit.pyuses theurlliblibrary to fetch content from external URLs provided by the user. This is a functional requirement to analyze page titles, descriptions, and accessibility for AI search engines.\n- [COMMAND_EXECUTION]: Thescripts/verify.shbash script executesgreporripgrepto perform static analysis of project files. It identifies prohibited marketing terminology and verifies basic structural requirements like the presence of a single H1 tag.\n- [PROMPT_INJECTION]: The skill facilitates the ingestion of external content, which represents a surface for indirect prompt injection.\n - Ingestion points: Raw writing samples provided by the user are stored in
02-DOCS/raw/brand/, and metadata is retrieved from external websites viascripts/seo_audit.py.\n - Boundary markers: Absent. The skill instructions do not specify the use of delimiters or warnings when the agent processes these raw text samples.\n
- Capability inventory: The skill performs network requests through
scripts/seo_audit.py, executes local search commands viascripts/verify.sh, and manages project documentation by writing to the02-DOCS/directory and theCLAUDE.mdfile.\n - Sanitization: Absent. Content extracted from external sources is processed as plain text without specialized filtering for instructions designed to influence the agent's behavior.
Audit Metadata