gingiris-seo-geo-agent

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands using curl to push content updates to the IndexNow API. This process utilizes owner-configured variables (such as [DOMAIN] and [KEY]) defined in the project setup.
  • [EXTERNAL_DOWNLOADS]: The SOP involves frequent data retrieval from several well-known SEO and analytics services, including Google Search Console, Google Analytics 4 (GA4), and DataForSEO, to monitor site performance and keyword metrics.
  • [PROMPT_INJECTION]: The skill includes instructions to ingest and analyze external data from competitor blogs for keyword research and trend analysis. This constitutes an indirect prompt injection surface where content from third-party websites enters the agent's context.
  • Ingestion points: Competitor blogs and search engine results pages (SERPs) analyzed via DataForSEO or direct scraping.
  • Boundary markers: Not explicitly defined for the scraping process, though the agent is instructed to focus on keyword and intent extraction.
  • Capability inventory: Subprocess execution via curl, file writing for blog post generation, and network operations for API interaction.
  • Sanitization: Not explicitly documented; however, the behavior is an inherent part of the primary SEO automation use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 05:43 AM
Security Audit — agent-trust-hub — gingiris-seo-geo-agent