seo-angle-finder
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external competitor URLs via the WebFetch tool and ingests documents from Google Drive using the google-workspace MCP. This creates an entry point for indirect prompt injection, where malicious instructions embedded in those external sources could potentially influence the agent's output.\n
- Ingestion points: External competitor web pages summarized by WebFetch, and files retrieved from Google Drive folders (e.g., SEO Knowledge Base and transcripts).\n
- Boundary markers: The instructions do not specify the use of delimiters or clear warnings to the agent to ignore any instructions found within the retrieved content.\n
- Capability inventory: The skill's primary actions involve analysis, summarization, and human-in-the-loop validation; it does not demonstrate capabilities for sensitive local file access, arbitrary shell command execution, or unauthorized network exfiltration of personal data.\n
- Sanitization: There is no evidence of content sanitization or validation performed on the external data before it is processed by the agent.\n- [EXTERNAL_DOWNLOADS]: The documentation includes an installation command that fetches content from a GitHub repository (
github.com/peter-tu-zynkr/zynkr-skill-builder). This resource is owned by the skill's author and is used for standard setup purposes.
Audit Metadata