seo-prospect
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell and Python scripts (
preflight.sh,keyword_research.py, andprospect_finder.py) to manage API authentication and automate the prospecting workflow. - [PROMPT_INJECTION]: The skill possesses an Indirect Prompt Injection surface due to the ingestion of untrusted data:
- Ingestion points: The skill retrieves and processes data from external sources including Google Search results and on-page audits of third-party websites.
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between its primary instructions and the untrusted data being analyzed.
- Capability inventory: The skill uses
BashandWritecapabilities to handle the data and generate output files. - Sanitization: The instruction set does not define any sanitization or filtering procedures for the content fetched from external domains.
Audit Metadata