programmatic-seo-planner

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates data collection by instructing the agent to run local Python scripts from the site-content-catalog and reddit-post-finder skills. This capability is used to catalog competitor content and mine Reddit discussions for customer language.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted data from competitor websites and Reddit (Phase 1A, 1C). It lacks explicit boundary markers or content sanitization to isolate these external inputs. The agent's capability to execute shell commands and write files to the local directory could be exploited if malicious instructions are embedded in the scraped content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 10:48 AM
Security Audit — agent-trust-hub — programmatic-seo-planner