seo-coach
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, which presents a potential surface for instructions hidden in data to influence the agent.\n
- Ingestion points: The skill ingests data from web search results, browser/page scraping, and the
get_project_contexttool.\n - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the retrieved external content.\n
- Capability inventory: The skill has the ability to read and update shared project context (
get_project_context,update_project_context) and retrieve Google Search Console performance data.\n - Sanitization: There are no explicit requirements for the agent to sanitize, escape, or validate the content fetched from the web or project memory before processing it.
Audit Metadata