buying-signal-monitor

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the unifapi-agent/agents plugin and the unifapi data skill from the vendor's marketplace. These downloads are central to the skill's functionality and originate from the same vendor as the skill itself.
  • [PROMPT_INJECTION]: The skill is designed to process untrusted data from public social media posts, creating a surface for indirect prompt injection where malicious content in a post could attempt to influence the agent's scoring or outreach suggestions.
  • Ingestion points: Data is ingested via the unifapi tool using endpoints like x/tweets/search/recent and linkedin/search/posts as described in SKILL.md.
  • Capability inventory: The skill is restricted to read-only research and lacks the capability to execute commands, write files, or perform automated network exfiltration.
  • Boundary markers: The instructions tell the agent to quote source posts verbatim but do not provide specific technical delimiters for the external content.
  • Sanitization: No explicit sanitization of social media content is mentioned, but the skill includes a lead-scoring rubric and requires human verification for any signals marked as "inferred" before outreach occurs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:06 PM
Security Audit — agent-trust-hub — buying-signal-monitor