onlyfans-account-health
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates within its stated purpose by fetching creators' revenue, subscriber, and traffic statistics from OnlyFansAPI endpoints (app.onlyfansapi.com). All network activity is directed to the vendor's own infrastructure.
- [SAFE]: Security best practices are enforced through explicit developer instructions, such as 'Never print or commit secrets' and the requirement to validate next-page URLs before providing credentials, mitigating potential token leakage.
- [SAFE]: The skill requests permission to connect vendor-provided Model Context Protocol (MCP) servers (docs.onlyfansapi.com and app.onlyfansapi.com). This provides the agent with structured access to documentation and tools in a transparent, user-consented manner.
- [SAFE]: While the skill ingests external data from API responses (earnings records and subscriber metrics), the risk of indirect prompt injection is minimal due to the skill's restricted capability set, which lacks dangerous operations like shell command execution or file modification.
Audit Metadata