hacker-news
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill's documentation includes instructions to install additional agent components using
npx skills add unifapi-agent/agents. This command executes the vendor's official package to set up the environment. - [EXTERNAL_DOWNLOADS]: The skill utilizes a remote Model Context Protocol (MCP) server hosted at
mcp.unifapi.comand references technical documentation atdocs.unifapi.com. These endpoints are managed by the skill author and are used for legitimate API connectivity and support. - [SAFE]: No evidence of prompt injection, data exfiltration, or persistence mechanisms was found. The skill is explicitly described as read-only and lacks any embedded executable scripts or obfuscated logic.
Audit Metadata