local-pack-audit

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADS
Full Analysis
  • [NO_CODE]: The skill consists solely of Markdown files (README.md, SKILL.md, and methodology.md) providing instructions and guidance. It contains no executable scripts, binaries, or configuration files that run code on the host system.
  • [EXTERNAL_DOWNLOADS]: The documentation references external installation paths for plugins (unifapi-agent/agents) and MCP servers via the author's official website (unifapi.com). These resources are consistent with the identified author and service provider, posing no unexpected third-party risk.
  • [PROMPT_INJECTION]: The instructions establish a restricted persona ("local-search analyst") and explicitly enforce safety guardrails such as "read-only research," "eyes not hands," and "it never touches the business's Google Business Profile." No malicious injection patterns or bypass attempts were found.
  • [DATA_EXFILTRATION]: The skill is designed to process public map and search engine results. It does not attempt to access sensitive local files, environment variables, or private credentials. Data retrieval is conducted via an OAuth-secured MCP connection to the specified vendor service.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:06 PM
Security Audit — agent-trust-hub — local-pack-audit