seo-metadata-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The README.md provides installation instructions using 'npx skills add' pointing to the author's own repository ('simbajigege/book2skills'). This represents a standard vendor-provided installation mechanism for adding skills.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and audit untrusted HTML and URL data provided by the user. While this creates a surface for potential indirect prompt injection, the risk is minimal as the skill lacks high-privilege capabilities such as shell access or network exfiltration. * Ingestion points: User-provided URLs and HTML snippets (SKILL.md). * Boundary markers: None explicitly defined in the instructions. * Capability inventory: Limited to generating text-based SEO reports and recommendations. * Sanitization: Not explicitly defined in the prompt logic.
- [SAFE]: The skill demonstrates legitimate intent through a transparent diagnostic methodology, providing clear citations to source material and focusing solely on SEO analysis without suspicious background activity.
Audit Metadata