book-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a bash helper script (
scripts/crawlora.sh) to perform network requests viacurl. The script implements strong security controls, including method restriction (GET only), path validation to prevent traversal, and a strict allow-list for API routes using both static matching and anchored regular expressions. - [CREDENTIALS_UNSAFE]: The skill requires a
CRAWLORA_API_KEYprovided via environment variable. The implementation follows security best practices by validating the key's format and passing it tocurlusing a temporary, permission-restricted configuration file (chmod 600) to prevent the key from appearing in process listings or logs. - [DATA_EXFILTRATION]: Network communication is limited to the vendor's official API endpoint (
api.crawlora.net). The data flow is restricted to retrieving book-related metadata, author bibliographies, and reviews from public sources (Goodreads, Apple Books, Audible). - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted book metadata and reviews from external platforms. While this represents a surface for indirect prompt injection (e.g., malicious instructions hidden in a book review), the skill returns structured JSON and does not execute instructions from the retrieved data. The ingestion is guarded by the context of book research.
Audit Metadata