seo
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by fetching and analyzing untrusted external data using the
web_fetchtool to perform SEO audits, SERP analysis, and AEO visibility testing. While this is the intended purpose of the skill, it lacks explicit boundary markers or sanitization logic to prevent the agent from following instructions potentially embedded in the fetched HTML or third-party content. This ingestion surface, combined with tools for command execution (bash) and file modification (write_to_file,replace_file_content), creates a vulnerability to multi-step prompt injection attacks.\n - Ingestion points: External website content and SERP data retrieved via
web_fetchacross all audit and optimization modes (referenced inSKILL.md,references/aeo.md,references/technical.md, andreferences/onpage.md).\n - Boundary markers: Absent; the instructions do not provide specific delimiters or 'ignore' directives for processed web data.\n
- Capability inventory: The skill environment includes
bash,view_file,write_to_file,replace_file_content, andgrep_search.\n - Sanitization: Absent; there is no documented procedure for filtering or escaping external content before the agent processes it or acts upon its analysis.
Audit Metadata