seo-audit
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and analyzes content from third-party websites for SEO diagnosis, which introduces an indirect prompt injection attack surface where embedded malicious text could attempt to manipulate the agent's logic.\n
- Ingestion points: Target website HTML and metadata accessed via
web_fetchandcurlas specified inSKILL.md.\n - Boundary markers: The instructions do not provide explicit delimiters or instructions to the agent to disregard commands within the audited data.\n
- Capability inventory: The agent is granted capabilities for network access, browser script execution, and local file reading.\n
- Sanitization: No data sanitization or filtering procedures are described for the external content before analysis.\n- [COMMAND_EXECUTION]: The skill specifies the use of shell-based network utilities like
curland browser-level DOM queries to extract SEO-related information.\n- [EXTERNAL_DOWNLOADS]: The skill contains references to trusted external services and diagnostic tools, including Google Search Console and the Rich Results Test.
Audit Metadata