seo-content-brief

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill follows its described purpose of SEO planning. No evidence of obfuscation, data exfiltration, or persistence mechanisms was found.
  • [COMMAND_EXECUTION]: The skill uses the infsh (inference.sh) CLI to run applications like tavily/search-assistant and exa/search. These tools are part of the vendor's ecosystem and are used for legitimate content analysis.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests installing additional related skills from the inference-sh organization via npx. These are trusted vendor resources.
  • [PROMPT_INJECTION]: The skill retrieves content from external search results to build briefs, which presents a surface for indirect prompt injection. However, this risk is inherent to search-based tasks and is not an intentional exploit within the skill code.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 05:20 PM