seo-research

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses a set of specialized tools (hyperseo_*) provided by the vendor 'hyperfx-ai'. All operations are consistent with the skill's stated purpose of providing data-driven SEO insights. No suspicious metadata, obfuscation, or hardcoded credentials were found.- [COMMAND_EXECUTION]: The skill documentation includes guidance for using google_search_console_query_insights, a tool that executes SQL-like queries against Search Console data. The agent is provided with clear query templates to ensure safe and predictable tool behavior.- [PROMPT_INJECTION]: As the skill ingests and analyzes data from external web sources (via hyperseo_serp_results and hyperseo_ai_overview), it possesses an inherent attack surface for indirect prompt injection. Maliciously crafted web content could attempt to influence the agent's interpretation during an audit.
  • Ingestion points: External search data and Search Console query results.
  • Boundary markers: The instructions do not define clear delimiters for isolating untrusted data.
  • Capability inventory: Tool-based SQL execution and network-enabled SEO data retrieval.
  • Sanitization: No specific content sanitization logic is detailed in the reference files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 04:20 AM