seo-competitor-pages
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate SEO-related tasks, such as generating feature matrices and evaluating schema markup. The use of tools like
WebFetchandBashis consistent with the skill's stated objective of gathering and processing public web data. - [PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection because it retrieves and processes content from external websites.
- Ingestion points: Competitor product pages fetched using the
WebFetchtool (SKILL.md). - Boundary markers: The instructions do not define clear delimiters to separate untrusted external content from the agent's internal instructions.
- Capability inventory: The skill is configured with access to
Read,Grep,Glob,Bash, andWebFetch(SKILL.md). - Sanitization: There are no explicit requirements for sanitizing or validating external data before it is incorporated into the generated content.
- Assessment: This finding is inherent to the skill's primary function of analyzing live web content and is considered low risk in this context.
Audit Metadata