agentkit-seo

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data, such as public URLs and user-supplied assets (LinkedIn profiles, CVs), creating an ingestion surface for potential indirect prompt injection attacks.\n
  • Ingestion points: The routing and intake workflows in SKILL.md specify fetching public material and inspecting user-supplied exports or local files.\n
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in SKILL.md to protect against instructions in external content.\n
  • Capability inventory: SKILL.md orchestrates multiple platform-specific modules that process file and web data.\n
  • Sanitization: There is no evidence of content sanitization or validation for ingested external data described in SKILL.md.\n- [EXTERNAL_DOWNLOADS]: The skill includes links to an external GitHub repository and project documentation.\n
  • Evidence: References to https://github.com/agentkit-seo/agentkit-seo and https://agentkit-seo.github.io/ are listed for user information in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:49 PM
Security Audit — agent-trust-hub — agentkit-seo