web-analytics-agent-skill
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires downloading the core application logic and dependencies from an external repository (github.com/SeoToolkit/web-analytics-agent-skill.git).
- [INDIRECT_PROMPT_INJECTION]: The skill ingests search query strings and landing page titles from Google Search Console, GA4, and Bing Webmaster Tools, which are externally influenced and could contain hidden instructions.
- Ingestion points: API response processing in
scripts/analyze_gsc.py,scripts/ga4_both.py, andscripts/bing_webmaster.py. - Boundary markers: None identified; the skill processes and prints API data directly without delimiters or instruction-bypass warnings.
- Capability inventory: The skill can write files (weekly JSON reports) and output data directly into the agent's interaction context.
- Sanitization: No sanitization, escaping, or filtering of the retrieved search queries or metadata was found in the provided implementation snippets.
Audit Metadata