competitive-seo-intel
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill requires the agent to ingest and analyze content from arbitrary competitor URLs and AI-generated search results. This creates a surface for indirect prompt injection, as malicious instructions could be embedded in the content of the pages the agent is instructed to read. There are no explicit instructions for the agent to treat this data as untrusted or to use boundary markers during processing.\n
- Ingestion points: Instructions to analyze external competitor websites (e.g., 'Analyze SEO strategy for [competitor URL]') and to test content within AI systems for visibility analysis.\n
- Boundary markers: Absent; the skill does not define specific delimiters to isolate external content from the agent's primary instruction set.\n
- Capability inventory: The skill utilizes web analysis capabilities and integrations with SEO tools (referenced as placeholders like ~~SEO 工具 and AHREFS_API_KEY).\n
- Sanitization: Absent; no logic is provided to filter or validate external content before it enters the agent's context.\n- [EXTERNAL_DOWNLOADS]: The documentation includes instructions for the user to install a library of related skills via a command-line utility (
npx skills add aaron-he-zhu/seo-geo-claude-skills). This involves fetching and executing code from an external repository managed by the author.
Audit Metadata