competitor-seo-analyzer

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted content from external competitor pages and data exports.
  • Ingestion points: The instructions specify collecting user pages, listing exports, and competitor content from external URLs or provided datasets in SKILL.md.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded within the analyzed content to prevent the agent from following malicious commands hidden in the data.
  • Capability inventory: The skill is primarily designed for data comparison and reporting; no high-risk capabilities such as arbitrary shell command execution or local file system modifications were identified in the provided files.
  • Sanitization: The workflow does not include steps to sanitize or filter input from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 05:39 AM
Security Audit — agent-trust-hub — competitor-seo-analyzer