seo-content-brief

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external websites and search engines, which could contain instructions intended to influence the agent's behavior.
  • Ingestion points: Data retrieved via sandbase_call_tool from services like exa_search, tavily_search, context_dev_scrape_markdown, and Google SERP results (SKILL.md).
  • Boundary markers: The instructions do not define explicit delimiters or headers to distinguish between system instructions and external data, nor do they instruct the agent to ignore instructions embedded in the retrieved content.
  • Capability inventory: The skill utilizes sandbase_call_tool to interact with external APIs and retrieve content (SKILL.md).
  • Sanitization: There are no requirements for sanitizing, escaping, or validating the content retrieved from external sources before it is processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — seo-content-brief