seo-mastery

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the AI agent to execute a shell command (ls) to probe specific local directories (e.g., ~/.claude/skills/, ~/.agent/skills/) to check for the presence of recommended companion skills on first activation (File: SKILL.md).\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing additional related skills from the same organization using the npx skills add command (Files: README.md, SKILL.md).\n- [PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection as it processes potentially untrusted external content.\n
  • Ingestion points: The skill analyzes and optimizes external data including page titles, meta descriptions, and schema markup (File: SKILL.md).\n
  • Boundary markers: Absent; the instructions do not provide delimiters or warnings to ignore embedded instructions within the processed SEO data.\n
  • Capability inventory: The skill instructs the agent to perform directory listings and package installations via shell commands (File: SKILL.md).\n
  • Sanitization: Absent; there are no instructions to validate, filter, or escape the metadata before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:05 PM
Security Audit — agent-trust-hub — seo-mastery