topical-authority-mapper

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local Python scripts such as 'catalog_site.py' and 'scrape_reddit.py' from associated modular skills to gather site data and community discussions. These are standard operations for the skill's stated SEO purpose.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to interact with well-known SEO service providers (including DataForSEO, Semrush, Ahrefs, and Keywords Everywhere) for keyword research and volume data. It also utilizes web search capabilities and scrapes content from Reddit.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting and processing content from external websites and social media platforms. Ingestion points: Competitor website content via site cataloging tools and community discussions via Reddit. Boundary markers: No explicit delimiters or 'ignore' instructions are defined for the ingested external data in the prompt templates. Capability inventory: Local shell command execution, network requests to external SEO APIs, and local file system writes to save reports. Sanitization: No specific sanitization or filtering of external text is defined before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 06:25 PM
Security Audit — agent-trust-hub — topical-authority-mapper