serp-analysis

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional markdown files and analysis templates. No executable code or suspicious automation logic is included in the skill files.
  • [PROMPT_INJECTION]: The skill processes untrusted external data by fetching and analyzing search results from the web (SERPs). This constitutes an attack surface for indirect prompt injection, where malicious instructions could be embedded in the content of analyzed websites. However, the skill's instructions focus on passive analysis (e.g., mapping features, documenting intent, and calculating difficulty), which minimizes the risk of the agent executing untrusted commands.
  • Ingestion points: Search results, AI Overview snippets, and content from top-ranking URLs (SKILL.md, analysis-templates.md).
  • Boundary markers: None identified.
  • Capability inventory: Uses WebFetch to retrieve search engine data.
  • Sanitization: Not explicitly implemented in the provided prompt templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 04:31 PM