competitor-launch-monitor

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs read-only research of public data through the unifapi skill and its associated MCP server at mcp.unifapi.com. This is legitimate vendor functionality for the competitive intelligence use-case.
  • [COMMAND_EXECUTION]: The README contains an npx skills add command for installation and /plugin commands for chat interfaces. These are standard installation patterns and do not present a security risk.
  • [DATA_EXFILTRATION]: No data exfiltration patterns were detected. The skill explicitly states it follows 'read-only' principles and does not post or touch user accounts.
  • [PROMPT_INJECTION]: No malicious prompt injection or bypass instructions were found. The 'Guardrails' section reinforces safe operating boundaries by restricting the agent to public data only.
  • [EXTERNAL_DOWNLOADS]: The skill references UnifAPI infrastructure (unifapi.com, mcp.unifapi.com) which is consistent with the skill's author (unifapi-agent). These are treated as trusted vendor resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 10:28 AM
Security Audit — agent-trust-hub — competitor-launch-monitor