seo-technical

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted content retrieved from external websites via the DataForSEO API (such as page titles, descriptions, and schema data). This creates an indirect prompt injection surface where malicious instructions embedded in a website's metadata could potentially influence the agent's behavior.
  • Ingestion points: Data ingested through on_page_audit.py which retrieves live website metadata and content.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or boundary markers when the agent processes the external API response.
  • Capability inventory: The skill has access to the Bash tool (used to run scripts like on_page_audit.py and preflight.sh) and the Write tool (used to create the .env file).
  • Sanitization: Absent. No sanitization or filtering logic is described for handling the data returned by the SEO audit tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 11:10 AM
Security Audit — agent-trust-hub — seo-technical