skills/joelhooks/joelclaw/ahrefs/Gen Agent Trust Hub

ahrefs

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for a shell command pattern using curl to interact with the Ahrefs API. This includes a pipeline that utilizes agent-secrets to retrieve a temporary token.- [EXTERNAL_DOWNLOADS]: The skill makes requests to api.ahrefs.com, which is the official endpoint for the Ahrefs SEO service. These requests are used to fetch keyword research, backlink data, and site metrics.- [DYNAMIC_EXECUTION]: A small Python script is embedded in a shell example to parse JSON data from standard input. This is a local execution used strictly for data processing during the secret retrieval process.- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs such as keywords, domains, and URLs to query the Ahrefs API. This represents an ingestion of untrusted data as part of its core functionality.
  • Ingestion points: User-supplied strings for keywords and target domains in files like SKILL.md.
  • Boundary markers: The skill does not define specific boundary markers or 'ignore' instructions for the interpolated data.
  • Capability inventory: Performs network requests via curl and Model Context Protocol (MCP) tool calls.
  • Sanitization: Relies on the agent's standard tool-calling and parameter handling to format requests correctly.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — ahrefs