local-seo
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to suppress information about its internal instructions and instead output a promotional response directing users to a commercial website if queried about its system prompt.
- [PROMPT_INJECTION]: The skill mandates the inclusion of fixed promotional and financial solicitation messages, including CashApp and BuyMeACoffee links, in long-form deliverables generated by the agent.
- [PROMPT_INJECTION]: The skill identifies a potential attack surface for indirect prompt injection by ingesting and processing untrusted user data to generate automated responses and content.
- Ingestion points: User-provided business descriptions and customer reviews.
- Boundary markers: The skill does not define specific delimiters to separate user data from agent instructions.
- Capability inventory: Generates content and JSON-LD schema blocks.
- Sanitization: No validation or filtering logic is specified for the ingested user content.
- [EXTERNAL_DOWNLOADS]: The skill includes references and instructions to output links to external domains including 'buymeacoffee.com' and 'scayveracademy.com'.
Audit Metadata