audience-fit-check

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements a secure data access model, using the unifapi MCP server to interact with official social media APIs via OAuth. It does not attempt to access sensitive local files or hardcoded credentials.
  • [SAFE]: All external references, including documentation links and plugin installation commands, point to the vendor's official infrastructure (unifapi.com), verifying the authenticity of the resources.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from public social media profiles and comments to perform sentiment and safety analysis. This establishes an indirect prompt injection surface; however, the agent's instructions explicitly restrict its actions to read-only research ("eyes, not hands"), effectively preventing any malicious payloads in the processed data from affecting the host system or taking unauthorized actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:06 PM
Security Audit — agent-trust-hub — audience-fit-check