seo-team-the-writer
Pass
Audited by Gen Agent Trust Hub on Mar 13, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from the live web to generate SEO content, creating a surface for indirect prompt injection. (1) Ingestion points: SERP analysis (Phases 1.1, 1.2) and competitor content parsing (Phases 1.5, 1.6) in SKILL.md. (2) Boundary markers: Absent; no specific delimiters or ignore instructions warnings are defined for external content. (3) Capability inventory: Execution of seocli commands and file system writes to workspace/seo/ (Phases 1 and 6). (4) Sanitization: None documented; content is processed into markdown/JSON for analysis and drafting.
- [EXTERNAL_DOWNLOADS]: Fetches search engine results and web page content using the seocli tool for informational analysis.
- [COMMAND_EXECUTION]: Executes the seocli tool locally to interact with the DataForSEO API and perform on-page SEO audits as part of the defined workflow.
Audit Metadata