seo-backlinks-profile

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's operations are consistent with its stated purpose as a specialized SEO auditing tool. It uses expected vendor-specific tools (DATA_...) to fetch backlink information.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present in the optional source verification step which scrapes content from external websites. This is handled as a standard risk factor for this use case.
  • Ingestion points: HTML content from external referring domains is fetched using the Firecrawl tool (mcp__firecrawl-mcp__firecrawl_scrape) in Step 8b.
  • Boundary markers: Absent; the skill does not explicitly define delimiters to separate scraped content from the agent's instructions, though the processing is restricted to link and attribute extraction.
  • Capability inventory: The skill utilizes SE Ranking data tools and performs local filesystem writes to generate auditing reports.
  • Sanitization: No explicit sanitization or validation of the external HTML content is specified in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 07:04 AM
Security Audit — agent-trust-hub — seo-backlinks-profile