onlyfans-ai-chatbot
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill provides explicit instructions for secure credential management, advising that
ONLYFANSAPI_API_KEYbe stored in server-side secrets and kept out of logs, prompts, browser code, and source control. - [PROMPT_INJECTION]: The documentation includes security guidance for preventing indirect prompt injection by instructing developers to separate trusted creator instructions from untrusted fan text, links, and chat history.
- [EXTERNAL_DOWNLOADS]: The skill references connections to official Model Context Protocol (MCP) servers and documentation provided by the vendor at
docs.onlyfansapi.comandapp.onlyfansapi.com. - [COMMAND_EXECUTION]: The skill promotes secure coding practices by recommending constant-time comparison for HMAC-SHA256 signature verification to prevent timing attacks.
Audit Metadata