skills/unifapi-agent/skills/instagram/Gen Agent Trust Hub

instagram

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The README.md documents installation via npx skills add unifapi-agent/agents. This refers to the vendor's own repository and is a standard procedure for adding supplementary skills.
  • [DATA_EXFILTRATION]: The skill is designed to communicate with https://mcp.unifapi.com to retrieve Instagram data. This domain is the official infrastructure for the UnifAPI service described in the skill metadata and documentation.
  • [PROMPT_INJECTION]: The skill processes untrusted external data by reading Instagram post captions and comments. This creates a surface for indirect prompt injection, where data from Instagram could contain instructions designed to influence the agent. However, the skill is explicitly read-only and lacks dangerous capabilities that would make such an injection high-risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 10:28 AM
Security Audit — agent-trust-hub — instagram