skills/leadmagic/gtm-skills/faq-seo/Gen Agent Trust Hub

faq-seo

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to ingest and process data from external, untrusted sources which represents a potential attack surface.
  • Ingestion points: Phase 1 of SKILL.md (Question Mining) directs the agent to gather data from Google People Also Ask (PAA) boxes, Reddit subreddits, and Quora questions.
  • Boundary markers: The instructions do not specify the use of clear delimiters or explicit directives to ignore embedded instructions within the mined content.
  • Capability inventory: The skill includes scripts/check-output.py which performs local file system reads for validation purposes.
  • Sanitization: There are no instructions for sanitizing or filtering the external content before it is processed into the output templates. This ingestion is a core part of the skill's primary purpose for SEO research.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 12:46 PM
Security Audit — agent-trust-hub — faq-seo