ai-seo

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface (Category 8).
  • Ingestion points: The skill instructions in SKILL.md direct the agent to read project context from .agents/product-marketing-context.md and process user-supplied queries and website content.
  • Boundary markers: Lacks defined boundary markers or specific negative constraints to prevent the agent from executing instructions that may be embedded within the project context or external tool data.
  • Capability inventory: The skill utilizes SEO and analytics tools such as semrush, ahrefs, gsc, and ga4 to retrieve and analyze external data.
  • Sanitization: No explicit sanitization, validation, or escaping protocols for retrieved content are specified in the instructions.
  • [SAFE]: The core logic of the skill consists of legitimate marketing advice and content templates derived from public SEO research.
  • [SAFE]: References to external domains like search.brave.com, llmstxt.org, and major search platforms are informational and target well-known, reputable services.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 11:10 PM
Security Audit — agent-trust-hub — ai-seo