skills/findbene/skills/seo-technical/Gen Agent Trust Hub

seo-technical

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted content from external URLs provided in arguments, which creates a surface for indirect prompt injection attacks where malicious instructions on a scanned page could influence the agent's behavior.
  • Ingestion points: Untrusted content is retrieved from external websites using the WebFetch tool based on the [url] argument.
  • Boundary markers: There are no specified delimiters or instructions (e.g., 'ignore embedded commands') provided to the agent to isolate the audited content from its system instructions.
  • Capability inventory: The skill utilizes Bash, WebFetch, Read, Grep, and Glob, providing a significant execution surface if an injection occurs.
  • Sanitization: The instructions lack any specific validation or sanitization steps for the data retrieved from the web before it is analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 06:44 PM
Security Audit — agent-trust-hub — seo-technical