internal-linking

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection attack surface due to the combination of data ingestion and local capabilities. Ingestion points: The skill reads untrusted data from local site content, sitemaps, and public web pages via browser or search tools (SKILL.md). Boundary markers: Instructions do not provide specific delimiters to help the agent ignore potential commands within the external content. Capability inventory: The skill is authorized to modify local files or connected CMS content ('Apply approved edits'). Sanitization: No explicit sanitization or escaping of external content is described. Remediation: Implement strict delimiters for external content processing and maintain human-in-the-loop validation for all file-modifying operations.
  • [EXTERNAL_DOWNLOADS]: The skill neutrally references the 'Suganthan-Mohanadasan/Suganthans-GSC-MCP' GitHub repository as a tool for Google Search Console integration. This is a reference to a well-known service and does not involve automated downloads of unverified code by the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 09:18 AM
Security Audit — agent-trust-hub — internal-linking