geo-update
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches updates, including instructions and scripts, from the author's GitHub repository at
github.com/zubair-trabzada/geo-seo-claude.git. - [COMMAND_EXECUTION]: Executes shell commands such as
git cloneto retrieve updates,difffor version comparison,cpfor file deployment, andpip installfor dependency management. - [DYNAMIC_EXECUTION]: Automatically grants execution permissions using
chmod +xto downloaded Python scripts and hook files within the agent's local environment. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from a remote repository that could influence agent behavior if the source is modified to include hidden instructions. Ingestion points: Remote repository content is cloned from
https://github.com/zubair-trabzada/geo-seo-claude.git(SKILL.md). Boundary markers: None; there are no delimiters or specific instructions to ignore embedded prompts in the downloaded files. Capability inventory: The skill possessesBashandWritecapabilities, and performs shell commands and permission modifications (SKILL.md). Sanitization: None; the skill copies remote files directly into the active skill and agent directories without integrity checks or content filtering.
Audit Metadata