seo-sitemap

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of instructional markdown and does not bundle any Python, Node.js, or other executable scripts.
  • [PROMPT_INJECTION]: The skill is designed to ingest and validate external XML sitemaps, which represents a surface for indirect prompt injection. Malicious instructions could be embedded within the sitemap content or metadata to influence the agent's behavior during the analysis phase.
  • Ingestion points: XML sitemap files and website content during the validation and crawl comparison steps (SKILL.md).
  • Boundary markers: The skill does not define explicit delimiters or instructions to the agent to ignore potentially malicious commands embedded in the external XML data.
  • Capability inventory: The skill utilizes the agent's file system capabilities to generate output files such as sitemap.xml, VALIDATION-REPORT.md, and STRUCTURE.md.
  • Sanitization: No specific sanitization or filtering logic is mentioned for the content extracted from sitemaps beyond format and status code validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 02:40 PM
Security Audit — agent-trust-hub — seo-sitemap