programmatic-seo
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists exclusively of Markdown documentation and YAML configuration. There are no executable scripts, shell commands, or third-party package dependencies included in the skill files, which significantly limits the direct attack surface.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process structured data and local marketing context files to generate web content. While this represents a potential surface for indirect prompt injection if the source data is malicious, the skill provides extensive guidance on data contracts and quality sampling to mitigate risks.
- Ingestion points: External structured data and .agents/marketing-context.md as described in SKILL.md.
- Boundary markers: The instructions do not define specific delimiters for separating data from instructions.
- Capability inventory: The skill relies on the agent's base capabilities for content generation and does not define its own tools, scripts, or network operations.
- Sanitization: The references/programmatic-system.md file mandates strict data contracts, required field validation, and manual review cycles to ensure data integrity.
Audit Metadata