auction-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/crawlora.shfacilitates interaction with the Crawlora API usingcurl. The script is hardened against injection by using strict regex-based allowlisting for API paths and parameters. - [CREDENTIALS_UNSAFE]: The skill uses an API key provided via the
CRAWLORA_API_KEYenvironment variable. The helper script implements secure handling by writing this key to a temporary configuration file with restricted permissions (chmod 600) and passing it tocurlusing the--configflag, which ensures the secret does not appear in process lists or logs. - [EXTERNAL_DOWNLOADS]: The skill communicates with
api.crawlora.netto retrieve auction data. This is a vendor-owned resource belonging to the author (crawlora-org) and is the primary intended function of the skill. - [DATA_EXFILTRATION]: The helper script includes explicit protections against Local File Disclosure (LFD). It rejects the
@character in query parameters and streams the request body viastdinwhen usingPOST, preventingcurlfrom being tricked into reading and uploading local system files.
Audit Metadata