seo-content-brief

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references installation scripts and related skills from the inference-sh GitHub organization. These are vendor-controlled resources used to set up the necessary environment and extend functionality.
  • [COMMAND_EXECUTION]: The skill relies on the infsh command-line tool to execute various search and analysis tasks. This is standard behavior for a tool-based SEO utility.
  • [PROMPT_INJECTION]: This skill ingests content from external URLs using the tavily/extract app for competitive research. This creates a surface for indirect prompt injection, as the agent processes untrusted data from the web. The evidence includes the use of infsh app run tavily/extract on competitor URLs in SKILL.md, with no explicit boundary markers or sanitization mentioned, though this is a common characteristic of web-analysis tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 04:25 PM
Security Audit — agent-trust-hub — seo-content-brief