seo-intel
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves crawling third-party websites and extracting content (titles, headings, body text) to generate SEO reports and site audits. This creates a surface for indirect prompt injection where malicious instructions embedded in external web pages could influence the agent's behavior during report generation.
- Ingestion points: Web page extraction described in references/site-audit-checks.md (Per-page extraction) and competitor crawling in references/content-gaps.md (Scope and crawl).
- Boundary markers: The instructions do not implement specific delimiters or 'ignore' directives to separate untrusted external content from the agent's core instructions.
- Capability inventory: The agent has the capability to write structured snapshot files and detailed reports to the workspace based on the ingested data.
- Sanitization: There is no evidence of sanitization or filtering logic applied to the extracted text to mitigate potential prompt injection attempts from external sources.
Audit Metadata