social-listening-brief

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes a remote Model Context Protocol (MCP) server at https://mcp.unifapi.com to retrieve live social media data. This is an official resource provided by the vendor for the skill's primary functionality.
  • [COMMAND_EXECUTION]: The README provides an installation command, npx skills add unifapi-agent/agents, which retrieves the marketing tools from the author's verified package registry.
  • [DATA_EXFILTRATION]: The agent is instructed to read local project configuration files, such as .agents/product-marketing.md, to determine search keywords and context. This behavior is confined to the project environment and does not target sensitive system files or credentials.
  • [PROMPT_INJECTION]: The skill processes untrusted public data from social media posts and comments. While this presents an indirect prompt injection surface, the risk is mitigated by the agent's restricted capabilities, which are limited to read-only data retrieval and report generation without any account-modification or command-execution permissions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 10:29 AM
Security Audit — agent-trust-hub — social-listening-brief