neighborhood-guide-opportunity
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill retrieves public SEO, news, and map data via the UnifAPI infrastructure (unifapi.com), which aligns with its stated purpose as a marketing strategist tool.
- [SAFE]: Installation commands and resource links point to official vendor-controlled domains and plugin repositories associated with unifapi-agent.
- [PROMPT_INJECTION]: The skill processes untrusted external data from search results and news feeds, creating a surface for indirect prompt injection. However, the impact is minimized by the skill's lack of dangerous capabilities like file writing or command execution.
- Ingestion points: Data retrieved from seo/serp, news/search, and local/search tools as described in SKILL.md.
- Boundary markers: None explicitly defined to separate external data from agent instructions.
- Capability inventory: Limited to analyzing data and generating markdown reports; no tools for system modification or network transmission of local files are present.
- Sanitization: No explicit filtering or sanitization of external content is specified.
Audit Metadata