goodday-api

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines interactions with the official and verified GoodDay API service at api.goodday.work over secure HTTPS connections.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys or secrets were found. The skill includes explicit instructions for users to provide their API token via the GOODDAY_API_TOKEN environment variable.
  • [PROMPT_INJECTION]: The content is strictly informational and does not contain any patterns intended to bypass agent safety filters or override system instructions.
  • [DATA_EXFILTRATION]: Network requests are restricted to the declared API endpoints, and there is no evidence of unauthorized data transfer to external or suspicious domains.
  • [COMMAND_EXECUTION]: The provided curl examples are standard API usage demonstrations and do not involve any unsafe or arbitrary shell command injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:14 AM
Security Audit — agent-trust-hub — goodday-api