app-market-opportunity-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process user-generated content from external app stores, which acts as an untrusted input surface.
- Ingestion points: Untrusted data enters the agent context via the
/appstore/reviews,/googleplay/reviews, and/appstore/app(description) endpoints as documented inreference/endpoints.mdandSKILL.md. - Boundary markers: The instructions lack explicit delimitation or "ignore instructions" wrappers for the external review text ingested by the agent.
- Capability inventory: The skill provides network access via
scripts/crawlora.shto a restricted set of vendor API routes. It has no arbitrary file-write, command execution, or evaluation capabilities. - Sanitization: The helper script
scripts/crawlora.shimplements defensive input handling, including query parameter encoding and standard input streaming for POST bodies, to prevent injection into the underlying shell command. - [SAFE]: The skill's implementation of
scripts/crawlora.shfollows security best practices to mitigate common attack vectors: - Credential Protection: The
CRAWLORA_API_KEYis passed tocurlusing a temporary configuration file with restricted permissions (chmod 600), preventing the secret from appearing in process lists (e.g.,psoutput). - Input Validation: The script uses a strict whitelist and regular expression matching for API paths, and it explicitly rejects suspicious characters (like
..,//,?, or#) that could be used for directory traversal or request smuggling. - Local File Protection: The script rejects the
@character in query parameters to preventcurlfrom inadvertently disclosing local system files.
Audit Metadata