off-page-seo

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [METADATA_POISONING]: The skill's YAML frontmatter declares writes: [], suggesting it has no file-writing capabilities. However, the body instructions explicitly describe writing results to .seo/backlink-targets.json and tracking project status in .seo/off-page-status.md. This discrepancy between the platform configuration and the skill's operational logic is misleading.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from the open web to identify link-building opportunities, creating a surface for indirect prompt injection.
  • Ingestion points: Data retrieved via mcp__exa__web_search_advanced_exa and crawling_exa tools is processed to extract domain and anchor text data.
  • Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded in crawled content.
  • Capability inventory: The skill has read access to brand context files, uses network search tools, and can spawn the mktg-backlink-prospector agent to continue research.
  • Sanitization: There is no mention of filtering or sanitizing the external data before it is incorporated into the agent's context or used to generate the .seo/backlink-targets.json file.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:06 PM
Security Audit — agent-trust-hub — off-page-seo