onlyfans-ai-chatbot

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill provides explicit instructions for secure credential management, advising that ONLYFANSAPI_API_KEY be stored in server-side secrets and kept out of logs, prompts, browser code, and source control.
  • [PROMPT_INJECTION]: The documentation includes security guidance for preventing indirect prompt injection by instructing developers to separate trusted creator instructions from untrusted fan text, links, and chat history.
  • [EXTERNAL_DOWNLOADS]: The skill references connections to official Model Context Protocol (MCP) servers and documentation provided by the vendor at docs.onlyfansapi.com and app.onlyfansapi.com.
  • [COMMAND_EXECUTION]: The skill promotes secure coding practices by recommending constant-time comparison for HMAC-SHA256 signature verification to prevent timing attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:56 AM
Security Audit — agent-trust-hub — onlyfans-ai-chatbot