seo-audit
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides detailed instructions for using the
ghost-clitool to perform metadata updates, social card configuration, and schema injection on Ghost CMS websites. These commands are integral to the skill's primary function of optimizing site visibility. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze content from external URLs to provide SEO recommendations.
- Ingestion points: Website content and metadata fetched via
curlor agent browser tools. - Boundary markers: The instructions do not specify the use of delimiters or specific warnings to ignore instructions embedded within the analyzed content.
- Capability inventory: The skill uses
ghost-clito perform write operations (metadata updates) to the target CMS. - Sanitization: No specific content sanitization or validation logic is detailed for the data being processed from the web.
- [DATA_EXPOSURE]: The documentation references the Ghost Admin API and technical requirements for updating posts, such as including the
updated_attimestamp for optimistic locking. No hardcoded credentials or sensitive local file paths were identified.
Audit Metadata