keyword-research
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the GitHub CLI (
gh repo view --json stargazerCount) to retrieve repository metadata as a metric for estimating the domain rating of websites. - [EXTERNAL_DOWNLOADS]: The skill fetches data from external search providers and scrapers, including Exa MCP (
web_search_advanced_exa,deep_search_exa) and Firecrawl, to gather live SERP data and autocomplete suggestions. - [DATA_EXFILTRATION]: Local business data from files such as
positioning.mdandaudience.mdis processed and used to generate search queries sent to external services. This behavior is required for the skill's primary function of creating brand-aligned content strategies. - [PROMPT_INJECTION]: The skill processes untrusted content from the public web, competitor blogs, and social platforms like Reddit, X, and Hacker News (via
/last30days). This ingestion of external data creates a surface for indirect prompt injection, where malicious instructions embedded in search results could attempt to influence the agent's behavior during analysis.
Audit Metadata