seo-keyword-insights
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists exclusively of instructional Markdown and YAML metadata. It does not include scripts, executables, or code dependencies that could execute malicious logic.
- [REMOTE_CODE_EXECUTION]: The skill uses specific tool names (e.g.,
dataforseo_v3_on_page_content_parsing_live) through an authorized gateway. It explicitly forbids direct provider URL calls and requires using thesandbase_call_toolpattern, which mitigates unauthorized remote code execution. - [CREDENTIALS_UNSAFE]: The instructions contain strict prohibitions against requesting, printing, or storing API keys in the research output. It mandates that authentication be handled by the SandBase gateway rather than the agent.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (website content, SERP results), it implements several safety layers. It instructs the agent to treat external content as 'evidence' rather than instructions, uses structured report templates, and includes failure handling for blocked or incomplete data, which limits the surface area for indirect injection attacks.
Audit Metadata