hacker-news

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill's documentation includes instructions to install additional agent components using npx skills add unifapi-agent/agents. This command executes the vendor's official package to set up the environment.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes a remote Model Context Protocol (MCP) server hosted at mcp.unifapi.com and references technical documentation at docs.unifapi.com. These endpoints are managed by the skill author and are used for legitimate API connectivity and support.
  • [SAFE]: No evidence of prompt injection, data exfiltration, or persistence mechanisms was found. The skill is explicitly described as read-only and lacks any embedded executable scripts or obfuscated logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 10:28 AM
Security Audit — agent-trust-hub — hacker-news