ai-seo

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the is-agentic tool, which is executed via npx. This is a developer utility for auditing website accessibility for AI agents. The tool is attributed to Vercel, which is a well-known and reputable service provider. Other references point to established SEO platforms like SEMrush, Ahrefs, and Google Search Console.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves analyzing external data such as website content, competitor pages, and user search queries, which represents a potential injection surface. However, the risk is mitigated as the skill serves as a knowledge base and does not provide high-privilege capabilities or unsafe data interpolation patterns.
  • Ingestion points: Processes website HTML, search query patterns, and competitor citation data during audits.
  • Boundary markers: Not explicitly implemented within the markdown-based knowledge files.
  • Capability inventory: No file system write operations, network exfiltration commands, or subprocess execution capabilities are defined in the skill scripts.
  • Sanitization: Not applicable for this knowledge-centric skill.
  • [SAFE]: The skill documentation encourages standard security and privacy best practices, such as granularly controlling AI bot access in robots.txt and using structured data for transparency. No persistence mechanisms, privilege escalation, or obfuscation techniques were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:15 AM
Security Audit — agent-trust-hub — ai-seo