prediction-markets-dome
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions include shell commands that use
python3 -cto programmatically parse JSON data from the local filesystem. - [CREDENTIALS_UNSAFE]: The setup process involves reading an API key from
~/.gooseworks/credentials.json. This is standard behavior for the vendor's own CLI and configuration management. - [DATA_EXFILTRATION]: Network requests are directed to
api.gooseworks.ai, which is the official endpoint provided by the skill author. The inclusion of authorization headers is required for the intended API functionality.
Audit Metadata