web-analytics-agent-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading the core application logic and dependencies from an external repository (github.com/SeoToolkit/web-analytics-agent-skill.git).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests search query strings and landing page titles from Google Search Console, GA4, and Bing Webmaster Tools, which are externally influenced and could contain hidden instructions.
  • Ingestion points: API response processing in scripts/analyze_gsc.py, scripts/ga4_both.py, and scripts/bing_webmaster.py.
  • Boundary markers: None identified; the skill processes and prints API data directly without delimiters or instruction-bypass warnings.
  • Capability inventory: The skill can write files (weekly JSON reports) and output data directly into the agent's interaction context.
  • Sanitization: No sanitization, escaping, or filtering of the retrieved search queries or metadata was found in the provided implementation snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — web-analytics-agent-skill