programmatic-seo

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists exclusively of Markdown documentation and YAML configuration. There are no executable scripts, shell commands, or third-party package dependencies included in the skill files, which significantly limits the direct attack surface.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process structured data and local marketing context files to generate web content. While this represents a potential surface for indirect prompt injection if the source data is malicious, the skill provides extensive guidance on data contracts and quality sampling to mitigate risks.
  • Ingestion points: External structured data and .agents/marketing-context.md as described in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters for separating data from instructions.
  • Capability inventory: The skill relies on the agent's base capabilities for content generation and does not define its own tools, scripts, or network operations.
  • Sanitization: The references/programmatic-system.md file mandates strict data contracts, required field validation, and manual review cycles to ensure data integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 11:56 AM
Security Audit — agent-trust-hub — programmatic-seo