dental-reputation-benchmark

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external MCP server at https://mcp.unifapi.com and provides instructions to install packages such as unifapi-agent/agents and unifapi. These resources are provided by the skill's author (UnifAPI) and are required for the intended functionality of gathering live market evidence.
  • [PROMPT_INJECTION]: The skill processes untrusted data in the form of public review text sampled via local/search calls. This constitutes an indirect prompt injection surface. However, the skill's instructions focus on analyzing the text for marketing signals (such as city or service mentions) and do not involve executing commands derived from that text.
  • [DATA_EXFILTRATION]: The skill utilizes the unifapi tool to fetch public business listing data. It uses OAuth for authentication and does not attempt to access or exfiltrate sensitive local environment variables, credentials, or private files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 10:29 AM
Security Audit — agent-trust-hub — dental-reputation-benchmark