seo-content-brief
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external websites and search engines, which could contain instructions intended to influence the agent's behavior.
- Ingestion points: Data retrieved via
sandbase_call_toolfrom services likeexa_search,tavily_search,context_dev_scrape_markdown, and Google SERP results (SKILL.md). - Boundary markers: The instructions do not define explicit delimiters or headers to distinguish between system instructions and external data, nor do they instruct the agent to ignore instructions embedded in the retrieved content.
- Capability inventory: The skill utilizes
sandbase_call_toolto interact with external APIs and retrieve content (SKILL.md). - Sanitization: There are no requirements for sanitizing, escaping, or validating the content retrieved from external sources before it is processed by the LLM.
Audit Metadata