seo-keyword
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exposes the agent to indirect prompt injection by processing untrusted data from the web and third-party files.
- Ingestion points: The skill instructs the agent to pull data from 'Competitor keywords' (exports), 'Search console queries', 'Related searches', and 'Forum and community language' (e.g., Reddit, forums) as seen in Stage 1 of the research framework.
- Boundary markers: No explicit delimiters or instructions are provided to separate internal agent directives from the untrusted data being analyzed.
- Capability inventory: The agent is required to use browsing tools to inspect SERPs and file-handling tools to read exports, then generate structured SEO clusters and prioritization maps.
- Sanitization: There are no defined sanitization or validation steps to ensure that content gathered from external sources does not contain malicious instructions aimed at overriding the agent's behavior.
Audit Metadata