no-outlinks-audit

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Python scripts that execute curl via the subprocess module to fetch website framework signals, sitemaps, and page content.
  • [EXTERNAL_DOWNLOADS]: Fetches data from external domains provided by the user (sitemaps, robots.txt, and HTML/RSC payloads) to perform the audit.
  • [EXTERNAL_DOWNLOADS]: Recommends the installation and use of the @ahrefs/mcp-server, a well-known and trusted service for SEO data.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites (sitemaps and page content) which is then processed by the agent to generate a report. While this presents an attack surface where a malicious site owner could attempt to influence the agent's output, the skill uses regex-based parsing and specific SEO logic which limits the exploitability of such data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 08:43 AM
Security Audit — agent-trust-hub — no-outlinks-audit