med-spa-reputation-benchmark

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The README.md file contains instructions for installing the skill and its associated MCP server using commands like npx skills add unifapi-agent/agents and /plugin marketplace add unifapi-agent/agents. These resources are hosted on the author's official infrastructure and represent standard deployment patterns for this ecosystem.
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze public review text (SKILL.md), which constitutes a surface for indirect prompt injection. However, the risk is limited as the skill's instructions focus on deterministic calculations and specific metrics (velocity, volume, rating) rather than open-ended execution based on review content.
  • [COMMAND_EXECUTION]: The skill utilizes a specialized data-access tool (unifapi) to perform local search and SEO lookups. These operations are restricted to read-only public data and do not involve arbitrary shell command execution or system-level modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:06 PM
Security Audit — agent-trust-hub — med-spa-reputation-benchmark