audience-fit-check

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill connects to the vendor's official API endpoint at mcp.unifapi.com to fetch public profile data, posts, and engagement metrics from social media platforms.
  • [COMMAND_EXECUTION]: Documentation includes instructions for the user to install additional agent components using the npx package runner from the vendor's repository.
  • [PROMPT_INJECTION]: The skill processes untrusted external data (social media posts and comments), which is a characteristic surface for indirect prompt injection.
  • Ingestion points: Social media posts and comment threads fetched from social media platforms via the unifapi tool.
  • Boundary markers: Not explicitly defined in the workflow, though the skill requires citing specific posts for all findings to ensure data provenance.
  • Capability inventory: Reading local project marketing files and calling external data APIs to fetch remote content.
  • Sanitization: No content filtering or sanitization of social media data is mentioned before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 10:29 AM
Security Audit — agent-trust-hub — audience-fit-check