competitor-launch-monitor
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs read-only research of public data through the
unifapiskill and its associated MCP server atmcp.unifapi.com. This is legitimate vendor functionality for the competitive intelligence use-case. - [COMMAND_EXECUTION]: The README contains an
npx skills addcommand for installation and/plugincommands for chat interfaces. These are standard installation patterns and do not present a security risk. - [DATA_EXFILTRATION]: No data exfiltration patterns were detected. The skill explicitly states it follows 'read-only' principles and does not post or touch user accounts.
- [PROMPT_INJECTION]: No malicious prompt injection or bypass instructions were found. The 'Guardrails' section reinforces safe operating boundaries by restricting the agent to public data only.
- [EXTERNAL_DOWNLOADS]: The skill references UnifAPI infrastructure (
unifapi.com,mcp.unifapi.com) which is consistent with the skill's author (unifapi-agent). These are treated as trusted vendor resources.
Audit Metadata