seo-program

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has a defined attack surface for indirect prompt injection because its core function involves ingesting and processing content from external, untrusted sources.
  • Ingestion points: The skill reads data from various external sources including Google Search Console, keyword research tools (Semrush, Ahrefs), AI visibility tools, call recording transcripts (demand signals), and collaborative platforms like Notion, Airtable, and Linear.
  • Boundary markers: There are no explicit instructions or boundary markers provided to the agent to treat external tool outputs or transcript data as potentially malicious or to ignore embedded instructions within that data.
  • Capability inventory: The agent is empowered to write to communication channels (Slack, Teams, email), update documentation tools (Notion, Google Docs), and create new markdown files within the repository.
  • Sanitization: The instructions focus on data accuracy and formatting (e.g., match types, scope windows) but do not specify sanitization or validation protocols for the content retrieved from these external APIs and tools before it is used to generate briefs or reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:31 AM
Security Audit — agent-trust-hub — seo-program