goudi

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of jailbreak attempts, safety bypass instructions, or system prompt extraction patterns. The instructions focus on structured analysis and constraint identification.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, sensitive file paths, or network exfiltration patterns were found. The skill does not perform any outbound requests or read-send operations.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill does not define any external dependencies (Python or Node.js) and contains no logic for downloading or executing remote code.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a natural attack surface as it processes untrusted user proposals. However, this risk is mitigated by explicit instructions that forbid writing code or modifying files while the grounding workflow is active, effectively preventing data-driven command execution.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill instructions do not utilize dynamic context triggers or shell-injected content in the markdown files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 04:49 PM
Security Audit — agent-trust-hub — goudi