seo-competitor-pages

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate SEO-related tasks, such as generating feature matrices and evaluating schema markup. The use of tools like WebFetch and Bash is consistent with the skill's stated objective of gathering and processing public web data.
  • [PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection because it retrieves and processes content from external websites.
  • Ingestion points: Competitor product pages fetched using the WebFetch tool (SKILL.md).
  • Boundary markers: The instructions do not define clear delimiters to separate untrusted external content from the agent's internal instructions.
  • Capability inventory: The skill is configured with access to Read, Grep, Glob, Bash, and WebFetch (SKILL.md).
  • Sanitization: There are no explicit requirements for sanitizing or validating external data before it is incorporated into the generated content.
  • Assessment: This finding is inherent to the skill's primary function of analyzing live web content and is considered low risk in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 11:34 AM
Security Audit — agent-trust-hub — seo-competitor-pages