aeo-recommend

Pass

Audited by Gen Agent Trust Hub on Mar 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to verify the existence of the tool's configuration file (cat .goose-aeo.yml) and to run analysis using the goose-aeo utility via npx. These commands are standard for the skill's operational workflow and are limited to the vendor's specific tooling.
  • [EXTERNAL_DOWNLOADS]: The skill lists goose-aeo as a dependency in its package.json and invokes it via npx. This package is a vendor-owned resource from 'athina-ai' (referenced as github.com/athina-ai/goose-aeo) and is essential for the skill's functionality.
  • [DATA_EXFILTRATION]: While the skill processes data from external AI search engines via the 'goose-aeo' tool, this represents the primary function of the skill (AEO analysis). There is no evidence of unauthorized data transfer to third-party domains outside of the expected vendor/OpenAI API calls required for the analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 26, 2026, 09:51 AM