audience-fit-check
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements a secure data access model, using the
unifapiMCP server to interact with official social media APIs via OAuth. It does not attempt to access sensitive local files or hardcoded credentials. - [SAFE]: All external references, including documentation links and plugin installation commands, point to the vendor's official infrastructure (unifapi.com), verifying the authenticity of the resources.
- [PROMPT_INJECTION]: The skill ingests untrusted data from public social media profiles and comments to perform sentiment and safety analysis. This establishes an indirect prompt injection surface; however, the agent's instructions explicitly restrict its actions to read-only research ("eyes, not hands"), effectively preventing any malicious payloads in the processed data from affecting the host system or taking unauthorized actions.
Audit Metadata