goodcase

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: Instructions within the skill attempt to steer the agent's behavior by prioritizing API results over internal knowledge.
  • [COMMAND_EXECUTION]: The skill executes shell-level curl commands to fetch data.
  • [EXTERNAL_DOWNLOADS]: Data and prompts are downloaded from the external API at goodcase.ai.
  • [DATA_EXFILTRATION]: Search keywords provided by the user are transmitted to an external service.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection from API content. 1. Ingestion points: Case study data from goodcase.ai/api/public. 2. Boundary markers: None identified. 3. Capability inventory: curl and text rendering. 4. Sanitization: No sanitization logic provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 03:42 AM
Security Audit — agent-trust-hub — goodcase