goofish-publish-item

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied item descriptions and images, which serves as an ingestion point for external data. This risk is effectively mitigated by the skill's operational design, which requires a manual confirmation from the user at Step 7 before the item_publish tool is executed.
  • Ingestion points: User-provided product descriptions and media inputs extracted in Step 2.
  • Boundary markers: No explicit prompt delimiters are used, but the skill enforces a behavioral boundary by requiring explicit user consent.
  • Capability inventory: mcp__goofish__item_publish, mcp__goofish__media_upload, and mcp__goofish__location_default.
  • Sanitization: Content is passed through a goofish-risk-guard scanner prior to publication to detect prohibited keywords or fraudulent patterns.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill retrieves the user's default shipping location and authentication status. These actions are within the functional scope of the vendor's listing tools and are necessary to complete the stated objective of posting a new item to the platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 05:37 AM
Security Audit — agent-trust-hub — goofish-publish-item