improve-aeo-geo

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to modify the user's codebase to implement SEO and AEO optimizations. It targets specific configuration files such as robots.txt, framework layouts (e.g., app/layout.tsx, header.php), and content files. This behavior is the primary intended function of the skill and is transparently documented in the workflow.
  • [SAFE]: The skill incorporates an indirect prompt injection surface by reading and processing external project files which are then used to inform code modifications.
  • Ingestion points: Reads local project files across multiple frameworks (Next.js, Nuxt, Astro, SvelteKit, Remix, WordPress, Hugo, Jekyll, 11ty).
  • Boundary markers: The skill does not explicitly define delimiters when reading file content into the agent context.
  • Capability inventory: The skill has file-write capabilities used to apply audited fixes.
  • Sanitization: No explicit content sanitization is described; however, the operations are limited to standard SEO/AEO metadata and structural changes.
  • [SAFE]: The skill references a companion website, aeo-audit.sh, for performance scoring. This is presented as a recommended user-facing tool and does not involve automated data exfiltration or silent background network requests.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 04:50 PM
Security Audit — agent-trust-hub — improve-aeo-geo