chrome-extension-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled script, scripts/crawlora.sh, which acts as a wrapper for the vendor's REST API. The script is implemented with security controls including a restricted path whitelist and checks to prevent command-line parameter injection.
  • [EXTERNAL_DOWNLOADS]: Network requests are performed against api.crawlora.net. This domain is the official API endpoint for the skill's author, crawlora-org, and is required for the skill's intended operation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data including extension descriptions and user reviews. Ingestion points are primarily the /search, /item, and /reviews API endpoints. While boundary markers are not explicitly provided in the prompt instructions, the skill handles this data through a helper script that provides sanitization for query parameters.
  • [SAFE]: A thorough security review of the instructions and bundled scripts found no malicious patterns. The script notably blocks curl's ability to read local files via query parameters, mitigating a common exfiltration vector.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — chrome-extension-research