ai-answer-gap

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs the user to install components via npx skills add unifapi-agent/agents and connect to an MCP server at https://mcp.unifapi.com. These resources are provided by the author (unifapi-agent) and are part of the intended installation process.
  • [COMMAND_EXECUTION]: The skill's workflow involves executing various data retrieval commands through the unifapi tool, specifically targeting SEO and GEO endpoints (e.g., geo/serp, seo/serp). These operations are used for legitimate competitive analysis and marketing research.
  • [DATA_EXFILTRATION]: While the skill performs network operations to the unifapi.com domain, these are restricted to public marketing data and utilize OAuth for secure authorization. There is no evidence of sensitive local file access or unauthorized data transmission.
  • [PROMPT_INJECTION]: The skill instructions do not contain any patterns intended to bypass AI safety guidelines or override system constraints.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external search engine result pages (SERPs) and LLM citations. However, the skill's capabilities are limited to analytical ranking and reporting, with no dangerous execution paths (such as file writes or shell commands) that could be exploited by malicious data in the retrieved content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:06 PM
Security Audit — agent-trust-hub — ai-answer-gap