creator-shortlist

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: A comprehensive analysis of the skill's instructions, metadata, and workflow found no security risks or malicious patterns.
  • [EXTERNAL_DOWNLOADS]: The skill references an external Model Context Protocol (MCP) server at mcp.unifapi.com. This server is part of the vendor's own infrastructure and is used for its stated purpose of fetching public social media data.
  • [DATA_EXFILTRATION]: The skill uses industry-standard OAuth for data access and does not attempt to read sensitive local files, environment variables, or credentials. It operates as a read-only research tool.
  • [PROMPT_INJECTION]: The skill ingests public data from social media platforms, which represents a surface for indirect prompt injection. However, because the skill lacks high-risk capabilities like command execution or file system writes, this surface does not present a significant security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:06 PM
Security Audit — agent-trust-hub — creator-shortlist