service-area-rank-audit

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of the 'unifapi-agent/agents' plugin and the 'unifapi' MCP server. These resources are hosted on the author's official domain (unifapi.com) and are necessary for the skill's data retrieval functions.
  • [DATA_EXPOSURE]: The skill reads project-specific configuration files such as '.agents/product-marketing.md' to obtain business context for auditing. This access is localized and intended for generating accurate search queries.
  • [PROMPT_INJECTION]: The skill processes data from external search results, which constitutes an indirect prompt injection surface. 1. Ingestion points: Search results from 'local/search', 'maps/search', and 'seo/serp' tools. 2. Boundary markers: Not present in the instructions. 3. Capability inventory: The skill is restricted to 'read-only' marketing research and has no capabilities for file-writing, code execution, or external data exfiltration. 4. Sanitization: No explicit output filtering is defined. The risk is considered minimal due to the lack of high-privilege capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:06 PM
Security Audit — agent-trust-hub — service-area-rank-audit