forge-seo

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill incorporates explicit safety instructions that prohibit the agent from executing instructions, hooks, or scripts found within fetched external content, which mitigates the risk of code execution.- [PROMPT_INJECTION]: The skill processes external HTML and metadata, creating a surface for indirect prompt injection. 1. Ingestion points: Public routes, rendered HTML, and sitemap files (SKILL.md). 2. Boundary markers: The skill lacks physical delimiters but uses a strict 'Inspection procedure' to limit agent interaction. 3. Capability inventory: Uses network 'fetch' and executes vendor-specific CLI tools like forge and fullstack-forge (SKILL.md). 4. Sanitization: Logical sanitization is present via instructions that explicitly forbid executing external code.- [COMMAND_EXECUTION]: The tool uses forge seo audit and fullstack-forge seo audit commands. These align with the vendor author context 'thethunderbolt' and are utilized in a restricted, read-only manner for SEO analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 06:48 PM
Security Audit — agent-trust-hub — forge-seo