app-store-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content retrieved from external app stores, such as app descriptions and user reviews.
  • Ingestion points: Data is fetched from Apple App Store, Google Play, and Chrome Web Store via API calls made in scripts/crawlora.sh.
  • Boundary markers: The skill returns data in JSON format but does not add specific delimiters or instructions to the LLM to ignore potentially malicious text within the retrieved descriptions or reviews.
  • Capability inventory: The skill uses curl to interface with the Crawlora API; no file-write or further network capabilities are present in the provided scripts.
  • Sanitization: While query parameters are URL-encoded, the descriptive text and review body content from the store listings are returned as provided by the upstream source without modification.
  • [COMMAND_EXECUTION]: The skill relies on a bash helper script scripts/crawlora.sh to facilitate API requests.
  • The script implements defensive programming practices including strict route validation via an allow-list of paths and anchored regular expressions to prevent path traversal or unauthorized API access.
  • It validates the format of the CRAWLORA_API_KEY to ensure it does not contain characters that could disrupt the configuration file generation or shell environment.
  • It uses a temporary curl configuration file (with appropriate permissions and cleanup) to pass the API key, ensuring the secret never appears in the system's process list.
  • [EXTERNAL_DOWNLOADS]: Communicates with the vendor's API at api.crawlora.net to retrieve research data.
  • The base URL is hardcoded in the script to prevent redirection via environment variables.
  • The communication is restricted to GET requests for the documented research routes only.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — app-store-research