ai-seo
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves analyzing external website content and AI search results, which constitutes an attack surface for indirect prompt injection.
- Ingestion points: The instructions direct the agent to check live search results on platforms like ChatGPT and Perplexity, and to analyze the content structure and citation patterns of competitor websites (SKILL.md, references/platform-ranking-factors.md).
- Boundary markers: The skill does not provide specific guidance on using delimiters or instruction-ignore blocks when the agent processes retrieved external content.
- Capability inventory: The skill references integration with common SEO tools (Semrush, Ahrefs, GSC, GA4) for data analysis, but these tools are well-known services (SKILL.md).
- Sanitization: There are no explicit instructions for sanitizing or filtering external data before the agent performs its visibility audit or extractability checks.
- [NO_CODE]: The skill consists entirely of instructional Markdown content and JSON-based evaluations, without any executable scripts or binary files.
Audit Metadata