competitor-research
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses a local credentials file at
~/.gooseworks/credentials.jsonto retrieve an API key. This key is used to authenticate requests toapi.gooseworks.ai. This is standard behavior for the vendor's own infrastructure. - [PROMPT_INJECTION]: The skill retrieves and processes data from external sources, such as web content via Scrapegraph and search results via Exa. This creates a surface for indirect prompt injection, as the agent may process instructions embedded in the retrieved third-party data. This is a common characteristic of research-oriented skills.
Audit Metadata