goofish-publish-item
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied item descriptions and images, which serves as an ingestion point for external data. This risk is effectively mitigated by the skill's operational design, which requires a manual confirmation from the user at Step 7 before the
item_publishtool is executed. - Ingestion points: User-provided product descriptions and media inputs extracted in Step 2.
- Boundary markers: No explicit prompt delimiters are used, but the skill enforces a behavioral boundary by requiring explicit user consent.
- Capability inventory:
mcp__goofish__item_publish,mcp__goofish__media_upload, andmcp__goofish__location_default. - Sanitization: Content is passed through a
goofish-risk-guardscanner prior to publication to detect prohibited keywords or fraudulent patterns. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill retrieves the user's default shipping location and authentication status. These actions are within the functional scope of the vendor's listing tools and are necessary to complete the stated objective of posting a new item to the platform.
Audit Metadata