seo-content-brief
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Employs the
infshCLI to perform search queries, extract content, and generate visual comparison tables via HTML-to-image conversion. - [EXTERNAL_DOWNLOADS]: Interacts with well-known search services, specifically Tavily and Exa, to retrieve real-time search engine data and competitor content.
- [PROMPT_INJECTION]: Identifies an indirect prompt injection surface as the skill processes and analyzes untrusted content extracted from third-party websites.
- Ingestion points: Data is ingested through content extraction tools like
tavily/extractand search results fromexa/search(SKILL.md). - Boundary markers: The provided templates do not currently implement specific delimiters or instructions to ignore embedded commands in the processed data.
- Capability inventory: The skill uses the
Bashtool to interact with CLI-based applications and search tools (SKILL.md). - Sanitization: There are no explicit content sanitization or validation steps documented for the data retrieved from external URLs.
Audit Metadata