link-building
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes an instruction in
SKILL.mdfor the agent to execute anlscommand on various hidden directories in the user's home folder (e.g.,~/.claude/skills/) to check for recommended companion skills upon activation.- [PROMPT_INJECTION]: The skill defines workflows for analyzing external backlink profiles and SEO reports, which constitutes a surface for indirect prompt injection. Ingestion points: External backlink exports in CSV or text format from SEO tools (referenced inreferences/link-audit.md). Boundary markers: Absent; the instructions do not define delimiters or warnings to ignore embedded instructions in the ingested data. Capability inventory: File reading, link profile analysis, and disavow file generation. Sanitization: Absent; the skill does not specify validation or sanitization steps for the data being processed.
Audit Metadata