goodday-api
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines interactions with the official and verified GoodDay API service at api.goodday.work over secure HTTPS connections.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys or secrets were found. The skill includes explicit instructions for users to provide their API token via the GOODDAY_API_TOKEN environment variable.
- [PROMPT_INJECTION]: The content is strictly informational and does not contain any patterns intended to bypass agent safety filters or override system instructions.
- [DATA_EXFILTRATION]: Network requests are restricted to the declared API endpoints, and there is no evidence of unauthorized data transfer to external or suspicious domains.
- [COMMAND_EXECUTION]: The provided curl examples are standard API usage demonstrations and do not involve any unsafe or arbitrary shell command injection patterns.
Audit Metadata