programmatic-seo
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill operates using intended platform tools (data_sites_tool and data_cms_tool) and adheres to standard workflows for Webflow site management.
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection due to its core functionality of ingesting external data.
- Ingestion points: Reads project context from
.claude/product-marketing-context.mdand supports bulk data imports via CSV and JSON files in Phase 4. - Boundary markers: Absent. The skill does not explicitly instruct the agent to ignore instructions embedded within the ingested data.
- Capability inventory: Capabilities are limited to Webflow CMS operations (listing sites, creating collections/fields/items). There are no shell execution, system-level file access, or unauthorized network operations detected.
- Sanitization: Absent. The skill expects the agent to parse and map data directly into CMS fields based on the provided schemas.
Audit Metadata