seo-content-brief
Pass
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill follows its described purpose of SEO planning. No evidence of obfuscation, data exfiltration, or persistence mechanisms was found.
- [COMMAND_EXECUTION]: The skill uses the
infsh(inference.sh) CLI to run applications liketavily/search-assistantandexa/search. These tools are part of the vendor's ecosystem and are used for legitimate content analysis. - [EXTERNAL_DOWNLOADS]: The documentation suggests installing additional related skills from the
inference-shorganization vianpx. These are trusted vendor resources. - [PROMPT_INJECTION]: The skill retrieves content from external search results to build briefs, which presents a surface for indirect prompt injection. However, this risk is inherent to search-based tasks and is not an intentional exploit within the skill code.
Audit Metadata