aeo-geo-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to audit and analyze external marketing blogs and websites, which introduces a surface for indirect prompt injection attacks. Malicious instructions embedded in audited content could potentially manipulate the agent's analysis or output.
  • Ingestion points: The workflow in SKILL.md requires reading external content, structured data, and technical configuration files (robots.txt).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to prevent it from following commands potentially hidden within the analyzed external content.
  • Capability inventory: The skill utilizes the agent's ability to browse the web and analyze text-based content.
  • Sanitization: The instructions do not describe any validation or sanitization of the external data before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill includes installation instructions that involve cloning a repository from GitHub (https://github.com/thatrebeccarae/claude-marketing.git). This resource is managed by the skill's author and constitutes a standard distribution channel.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:54 PM
Security Audit — agent-trust-hub — aeo-geo-optimizer