book-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a bash helper script (scripts/crawlora.sh) to perform network requests via curl. The script implements strong security controls, including method restriction (GET only), path validation to prevent traversal, and a strict allow-list for API routes using both static matching and anchored regular expressions.
  • [CREDENTIALS_UNSAFE]: The skill requires a CRAWLORA_API_KEY provided via environment variable. The implementation follows security best practices by validating the key's format and passing it to curl using a temporary, permission-restricted configuration file (chmod 600) to prevent the key from appearing in process listings or logs.
  • [DATA_EXFILTRATION]: Network communication is limited to the vendor's official API endpoint (api.crawlora.net). The data flow is restricted to retrieving book-related metadata, author bibliographies, and reviews from public sources (Goodreads, Apple Books, Audible).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted book metadata and reviews from external platforms. While this represents a surface for indirect prompt injection (e.g., malicious instructions hidden in a book review), the skill returns structured JSON and does not execute instructions from the retrieved data. The ingestion is guarded by the context of book research.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — book-research