service-area-rank-audit
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of the 'unifapi-agent/agents' plugin and the 'unifapi' MCP server. These resources are hosted on the author's official domain (unifapi.com) and are necessary for the skill's data retrieval functions.
- [DATA_EXPOSURE]: The skill reads project-specific configuration files such as '.agents/product-marketing.md' to obtain business context for auditing. This access is localized and intended for generating accurate search queries.
- [PROMPT_INJECTION]: The skill processes data from external search results, which constitutes an indirect prompt injection surface. 1. Ingestion points: Search results from 'local/search', 'maps/search', and 'seo/serp' tools. 2. Boundary markers: Not present in the instructions. 3. Capability inventory: The skill is restricted to 'read-only' marketing research and has no capabilities for file-writing, code execution, or external data exfiltration. 4. Sanitization: No explicit output filtering is defined. The risk is considered minimal due to the lack of high-privilege capabilities.
Audit Metadata