review-seo
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is strictly limited to a review role. It contains explicit instructions to only report findings and prohibits any edits or refactoring of the codebase.
- [PROMPT_INJECTION]: The skill processes external data such as project documentation (e.g.,
docs/frontend/SEO.md) and metadata from public web surfaces, which constitutes an indirect prompt injection surface. 1. Ingestion points: Project SEO documentation and metadata from changed web routes. 2. Boundary markers: The instructions do not define delimiters or isolation markers for untrusted content. 3. Capability inventory: The skill is restricted to a 'findings only' output format, with no capability for file modification, command execution, or network exfiltration. 4. Sanitization: No explicit sanitization or filtering of the ingested content is specified. The overall security risk is safe due to the skill's lack of actionable capabilities.
Audit Metadata