marketing-seo-audit
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external websites via
web_fetchand browser-based rendering tools during SEO audits, creating an indirect prompt injection surface. Ingestion points: Data from audited URLs enters the agent context through fetching tools likeweb_fetchor browser-based scripting. Boundary markers: The instructions do not specify explicit delimiters or "ignore instructions" tags for external content, though the agent is directed to adhere to a structured audit framework. Capability inventory: The skill's capabilities are limited to analyzing text and generating reports; it lacks write-access to the filesystem or the ability to execute system commands. Sanitization: The skill documentation notes thatweb_fetchstrips<script>tags during conversion, providing a measure of input sanitization. - [DATA_EXFILTRATION]: The skill utilizes network-enabled tools such as
web_fetchandcurlto retrieve data from user-specified external URLs for SEO analysis. These operations are intrinsic to the skill's primary purpose and do not involve sensitive local file access or exfiltration to unauthorized endpoints.
Audit Metadata