off-page-seo
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [METADATA_POISONING]: The skill's YAML frontmatter declares
writes: [], suggesting it has no file-writing capabilities. However, the body instructions explicitly describe writing results to.seo/backlink-targets.jsonand tracking project status in.seo/off-page-status.md. This discrepancy between the platform configuration and the skill's operational logic is misleading. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from the open web to identify link-building opportunities, creating a surface for indirect prompt injection.
- Ingestion points: Data retrieved via
mcp__exa__web_search_advanced_exaandcrawling_exatools is processed to extract domain and anchor text data. - Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded in crawled content.
- Capability inventory: The skill has read access to brand context files, uses network search tools, and can spawn the
mktg-backlink-prospectoragent to continue research. - Sanitization: There is no mention of filtering or sanitizing the external data before it is incorporated into the agent's context or used to generate the
.seo/backlink-targets.jsonfile.
Audit Metadata