google-search-ai-optimization

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The test suite in scripts/test_skill.py uses subprocess.run to execute the skill's internal validation and auditing scripts. These commands are constructed using static file paths for regression testing and do not involve unsanitized user input in a shell context.
  • [EXTERNAL_DOWNLOADS]: The scripts/audit_page.py utility utilizes the standard urllib library to fetch content from URLs provided as command-line arguments. This behavior is essential for its core purpose of auditing live web pages for SEO compliance. The skill also references official documentation from well-known Google and Web.dev domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it processes external, untrusted HTML content via scripts/audit_page.py. The tool uses a structural HTML parser to extract specific metadata and content signals, presenting this structured data to the agent for evaluation. No bypass or autonomous execution patterns were observed.
  • [SAFE]: The skill exhibits high-quality engineering practices, including a dedicated validation script and a clear separation between instructional guidance and functional tools. All file and network operations are restricted to the domain of web auditing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — google-search-ai-optimization