email-finder-tomba
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill interacts with the "api.gooseworks.ai" domain to proxy requests to the Tomba email service. This domain is controlled by the skill's author, gooseworks-ai.
- [SAFE]: API credentials are read from "~/.gooseworks/credentials.json" using a Python script. This is the standard mechanism for the agent to access its own credentials within the platform's ecosystem.
- [SAFE]: The skill processes external data returned from the Tomba API. While this represents an ingestion point for external content, the skill's capabilities are restricted to network requests to the vendor's proxy and do not involve executing untrusted code or modifying system settings.
Audit Metadata