Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The README.md documents installation via
npx skills add unifapi-agent/agents. This refers to the vendor's own repository and is a standard procedure for adding supplementary skills. - [DATA_EXFILTRATION]: The skill is designed to communicate with
https://mcp.unifapi.comto retrieve Instagram data. This domain is the official infrastructure for the UnifAPI service described in the skill metadata and documentation. - [PROMPT_INJECTION]: The skill processes untrusted external data by reading Instagram post captions and comments. This creates a surface for indirect prompt injection, where data from Instagram could contain instructions designed to influence the agent. However, the skill is explicitly read-only and lacks dangerous capabilities that would make such an injection high-risk.
Audit Metadata