ai-visibility-audit

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes untrusted data from external websites to identify citation gaps. Ingestion points: The skill utilizes the browser/markdown tool to read external web pages identified by geo/serp and geo/mentions/top-pages as described in SKILL.md. Boundary markers: There are no instructions providing boundary markers to isolate the external web content from the agent's logic. Capability inventory: The skill performs automated analysis of AI search result data and browser-rendered markdown content. Sanitization: The instructions do not describe any sanitization, filtering, or validation of the markdown content retrieved from external sources.
  • [EXTERNAL_DOWNLOADS]: The skill references and installs external resources originating from the vendor. The README.md directs users to install additional functionality using npx skills add unifapi-agent/agents and /plugin install unifapi@unifapi. It also requires a connection to a remote MCP server at https://mcp.unifapi.com to retrieve live audit evidence.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 07:03 PM
Security Audit — agent-trust-hub — ai-visibility-audit