goofish-risk-guard

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill primarily serves as a knowledge base and checklist for compliance scanning of marketplace listings and messages.
  • [PROMPT_INJECTION]: The skill includes a robust 'Decision Framework' that explicitly instructs the agent to refuse and explain user requests that attempt to bypass platform safety guidelines, such as hiding contact information or engaging in fraudulent transactions.
  • [COMMAND_EXECUTION]: The skill does not contain any shell commands, dynamic code execution patterns, or subprocess calls. The MCP tools used are for standard marketplace interactions (search, item retrieval).
  • [DATA_EXFILTRATION]: No sensitive local data, environment variables, or hardcoded credentials are accessed or transmitted. The skill focus is on processing provided listing text for safety compliance.
  • [SAFE]: Instructions regarding risk control recovery (RGV587/x5sec) provide legitimate guidance for users to resolve platform-level blocks manually via their browser.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 05:37 AM
Security Audit — agent-trust-hub — goofish-risk-guard