seo-hreflang

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external URLs via the WebFetch tool, creating an attack surface where malicious content on a scanned website could attempt to influence the agent's behavior.
  • Ingestion points: External websites accessed via user-provided URLs using the WebFetch tool.
  • Boundary markers: The instructions do not define clear delimiters or specific instructions for the agent to ignore potentially malicious embedded content within the HTML.
  • Capability inventory: The skill allows use of Bash, Grep, and Read tools, which could be misused if an injection succeeds.
  • Sanitization: There is no evidence of prompt-level sanitization for external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 09:23 AM
Security Audit — agent-trust-hub — seo-hreflang