seo-technical
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted content from external URLs provided in arguments, which creates a surface for indirect prompt injection attacks where malicious instructions on a scanned page could influence the agent's behavior.
- Ingestion points: Untrusted content is retrieved from external websites using the
WebFetchtool based on the[url]argument. - Boundary markers: There are no specified delimiters or instructions (e.g., 'ignore embedded commands') provided to the agent to isolate the audited content from its system instructions.
- Capability inventory: The skill utilizes
Bash,WebFetch,Read,Grep, andGlob, providing a significant execution surface if an injection occurs. - Sanitization: The instructions lack any specific validation or sanitization steps for the data retrieved from the web before it is analyzed.
Audit Metadata