auction-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/crawlora.sh facilitates interaction with the Crawlora API using curl. The script is hardened against injection by using strict regex-based allowlisting for API paths and parameters.
  • [CREDENTIALS_UNSAFE]: The skill uses an API key provided via the CRAWLORA_API_KEY environment variable. The helper script implements secure handling by writing this key to a temporary configuration file with restricted permissions (chmod 600) and passing it to curl using the --config flag, which ensures the secret does not appear in process lists or logs.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with api.crawlora.net to retrieve auction data. This is a vendor-owned resource belonging to the author (crawlora-org) and is the primary intended function of the skill.
  • [DATA_EXFILTRATION]: The helper script includes explicit protections against Local File Disclosure (LFD). It rejects the @ character in query parameters and streams the request body via stdin when using POST, preventing curl from being tricked into reading and uploading local system files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — auction-research