skills/grupous/gpus/geo-fundamentals/Gen Agent Trust Hub

geo-fundamentals

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides informational content and a local audit script without any high-risk behaviors.
  • [COMMAND_EXECUTION]: The skill includes a Python script (scripts/geo_checker.py) intended to be run by the agent. The script uses standard libraries and performs read-only operations on specified local directories to analyze file structure and metadata.
  • [DATA_EXPOSURE]: The script reads the contents of local .html, .jsx, and .tsx files to check for SEO/GEO signals. This access is restricted to the path provided by the user and is consistent with the tool's stated purpose of auditing web content.
  • [INDIRECT_PROMPT_INJECTION]: The script ingests untrusted data by reading local project files which could contain embedded instructions. However, the script only performs regex-based analysis and prints summary metrics, posing minimal risk of instruction override.
  • Ingestion points: scripts/geo_checker.py reads file content using pathlib.Path.read_text.
  • Boundary markers: Absent.
  • Capability inventory: None; the script only prints to standard output and does not perform network operations, file writes, or subprocess execution.
  • Sanitization: Absent; the script processes content using regex and string matching.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 09:20 AM
Security Audit — agent-trust-hub — geo-fundamentals