seo-audit
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to perform a read-only audit of the local project directory to provide SEO recommendations. It does not attempt to bypass security controls or execute unauthorized commands.
- [DATA_EXPOSURE]: While the skill reads project files (e.g.,
README.md, configuration files, and templates), it does not target sensitive system locations such as SSH keys, AWS credentials, or environment files. The gathered information is used solely to generate a local report. - [REMOTE_CODE_EXECUTION]: There are no patterns indicating the download or execution of remote scripts, package installations (npm/pip), or the use of dynamic execution functions like
eval()orexec(). - [PROMPT_INJECTION]: The instructions follow standard agent role-play guidelines and do not contain directives to ignore safety filters, override system prompts, or reveal internal instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it reads content from the user's codebase. However, because the skill's capabilities are limited to reading local files and writing markdown reports, the risk of an indirect injection causing systemic harm is negligible. No network exfiltration or code execution capabilities are present.
Audit Metadata