apk-teardown-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE]: The skill communicates with api.crawlora.net. This domain is the official infrastructure for the skill author, crawlora-org. The script properly handles the CRAWLORA_API_KEY by passing it to curl via a temporary configuration file with restricted permissions (chmod 600), preventing the secret from appearing in process monitoring tools like ps.
  • [COMMAND_EXECUTION]: The helper script scripts/crawlora.sh implements strict input validation. It enforces a whitelist of specific API endpoints, validates the HTTP method, and sanitizes the URL path to prevent path traversal or injection.
  • [DATA_EXPOSURE]: The script explicitly checks for and rejects the @ character in query parameters. This is a security best practice for curl-based wrappers to prevent an attacker from tricking the tool into reading and uploading local files via curl's file-reading shorthand.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Crawlora API, which creates a theoretical attack surface for indirect prompt injection if the API were to return malicious instructions.
  • Ingestion points: Results returned by scripts/crawlora.sh from the Crawlora API.
  • Boundary markers: Absent.
  • Capability inventory: Network access via curl to api.crawlora.net for APK teardown analysis.
  • Sanitization: The helper script performs rigorous validation on the API path and query arguments to prevent unauthorized tool use.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — apk-teardown-research