competitor-research

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses a local credentials file at ~/.gooseworks/credentials.json to retrieve an API key. This key is used to authenticate requests to api.gooseworks.ai. This is standard behavior for the vendor's own infrastructure.
  • [PROMPT_INJECTION]: The skill retrieves and processes data from external sources, such as web content via Scrapegraph and search results via Exa. This creates a surface for indirect prompt injection, as the agent may process instructions embedded in the retrieved third-party data. This is a common characteristic of research-oriented skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 01:06 PM