ai-answer-gap
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation instructs the user to install components via
npx skills add unifapi-agent/agentsand connect to an MCP server athttps://mcp.unifapi.com. These resources are provided by the author (unifapi-agent) and are part of the intended installation process. - [COMMAND_EXECUTION]: The skill's workflow involves executing various data retrieval commands through the
unifapitool, specifically targeting SEO and GEO endpoints (e.g.,geo/serp,seo/serp). These operations are used for legitimate competitive analysis and marketing research. - [DATA_EXFILTRATION]: While the skill performs network operations to the
unifapi.comdomain, these are restricted to public marketing data and utilize OAuth for secure authorization. There is no evidence of sensitive local file access or unauthorized data transmission. - [PROMPT_INJECTION]: The skill instructions do not contain any patterns intended to bypass AI safety guidelines or override system constraints.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external search engine result pages (SERPs) and LLM citations. However, the skill's capabilities are limited to analytical ranking and reporting, with no dangerous execution paths (such as file writes or shell commands) that could be exploited by malicious data in the retrieved content.
Audit Metadata