seo-audit
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill automatically downloads and installs the
@seomator/seo-auditpackage from the NPM registry and the Playwright Chromium browser to support its auditing functions. - [COMMAND_EXECUTION]: Executes multiple system commands including
npm,npx, andseomatorto perform system readiness checks, manage dependencies, and run technical audits. - [PROMPT_INJECTION]: Features an indirect prompt injection surface because the agent parses results from external websites which could contain malicious instructions designed to influence the agent's analysis.
- Ingestion points: Data retrieved from target URLs via the
seomator auditcommand (SKILL.md, Phase 3 and Phase 4). - Boundary markers: None identified; the instructions do not specify the use of delimiters or 'ignore' instructions for the tool's output.
- Capability inventory: The skill has the capability to execute shell commands and perform network operations via the seomator tool.
- Sanitization: No specific sanitization or validation of the website content is performed before it is analyzed by the agent.
Audit Metadata