seo-audit
Pass
Audited by Gen Agent Trust Hub on Mar 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains a 'Companion check' instruction directing the agent to run an 'ls' command to inspect local skill directories for specific installed tools.\n- [EXTERNAL_DOWNLOADS]: The skill suggests installing additional components from the vendor's repository using the 'npx skills add' command as part of its setup and maintenance instructions.\n- [PROMPT_INJECTION]: The skill analyzes untrusted data from external websites, which serves as an attack surface for indirect prompt injection. \n
- Ingestion points: Data enters the context through crawling external URLs, robots.txt, and sitemaps as specified in the audit checklists.\n
- Boundary markers: None are present in the instructions to delimit untrusted content or warn the model to ignore embedded instructions.\n
- Capability inventory: The skill includes capabilities for local file system inspection and package installation through shell commands.\n
- Sanitization: No validation or sanitization of content fetched from external websites is described in the skill files.
Audit Metadata