review-seo

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is strictly limited to a review role. It contains explicit instructions to only report findings and prohibits any edits or refactoring of the codebase.
  • [PROMPT_INJECTION]: The skill processes external data such as project documentation (e.g., docs/frontend/SEO.md) and metadata from public web surfaces, which constitutes an indirect prompt injection surface. 1. Ingestion points: Project SEO documentation and metadata from changed web routes. 2. Boundary markers: The instructions do not define delimiters or isolation markers for untrusted content. 3. Capability inventory: The skill is restricted to a 'findings only' output format, with no capability for file modification, command execution, or network exfiltration. 4. Sanitization: No explicit sanitization or filtering of the ingested content is specified. The overall security risk is safe due to the skill's lack of actionable capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 10:00 PM
Security Audit — agent-trust-hub — review-seo