med-spa-reputation-benchmark

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill connects to an external MCP server at mcp.unifapi.com and utilizes npx to install agent skills from the author's repository. These are identified as legitimate vendor resources aligned with the skill's functionality.
  • [DATA_EXFILTRATION]: The skill reads public business listing data through a designated API. No access to sensitive local files, environment variables, or private credentials was observed.
  • [SAFE]: The skill implements strong guardrails, explicitly stating its read-only nature and disclaiming medical advice. It uses OAuth for tool authentication, which is a standard secure practice for managing external service access.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 10:28 AM
Security Audit — agent-trust-hub — med-spa-reputation-benchmark