forge-seo
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill incorporates explicit safety instructions that prohibit the agent from executing instructions, hooks, or scripts found within fetched external content, which mitigates the risk of code execution.- [PROMPT_INJECTION]: The skill processes external HTML and metadata, creating a surface for indirect prompt injection. 1. Ingestion points: Public routes, rendered HTML, and sitemap files (SKILL.md). 2. Boundary markers: The skill lacks physical delimiters but uses a strict 'Inspection procedure' to limit agent interaction. 3. Capability inventory: Uses network 'fetch' and executes vendor-specific CLI tools like
forgeandfullstack-forge(SKILL.md). 4. Sanitization: Logical sanitization is present via instructions that explicitly forbid executing external code.- [COMMAND_EXECUTION]: The tool usesforge seo auditandfullstack-forge seo auditcommands. These align with the vendor author context 'thethunderbolt' and are utilized in a restricted, read-only manner for SEO analysis.
Audit Metadata