seo-prospect

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell and Python scripts (preflight.sh, keyword_research.py, and prospect_finder.py) to manage API authentication and automate the prospecting workflow.
  • [PROMPT_INJECTION]: The skill possesses an Indirect Prompt Injection surface due to the ingestion of untrusted data:
  • Ingestion points: The skill retrieves and processes data from external sources including Google Search results and on-page audits of third-party websites.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between its primary instructions and the untrusted data being analyzed.
  • Capability inventory: The skill uses Bash and Write capabilities to handle the data and generate output files.
  • Sanitization: The instruction set does not define any sanitization or filtering procedures for the content fetched from external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 11:11 AM
Security Audit — agent-trust-hub — seo-prospect