list-rules
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected in the skill files.
- [COMMAND_EXECUTION]: The skill provides templates and examples for running SEO reports via MCP tools (e.g.,
seo_run_report) and CLI commands, which are consistent with its stated purpose of rule discovery. - [PROMPT_INJECTION]: The skill defines a process to ingest data from tool outputs (specifically
structuredContent). While this creates a surface for indirect prompt injection (Category 8), the risk is low as the data source is limited to structured SEO rule metadata. Evidence chain: - Ingestion points: Tool output (
structuredContent) referenced inSKILL.md. - Boundary markers: None identified.
- Capability inventory: Execution of reporting tools (
seo_run_report) and CLI commands. - Sanitization: None mentioned in instructions.
Audit Metadata