collectibles-market-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a bash helper script scripts/crawlora.sh to interface with the Crawlora API. The script implements several security hardening measures:\n
  • It hardcodes the API base URL to https://api.crawlora.net/api/v1, preventing redirection of credentials to untrusted hosts.\n
  • It validates the CRAWLORA_API_KEY format to allow only safe characters (alphanumeric, dots, underscores, dashes).\n
  • It restricts allowed API routes to a specific list of 54 documented research endpoints, preventing unauthorized API surface access.\n
  • It uses a temporary, restricted-permission configuration file (chmod 600) to pass the API key to curl, ensuring the secret does not appear in the system's process list.\n- [CREDENTIALS_UNSAFE]: The skill requires a CRAWLORA_API_KEY to be set in the environment. The implementation follows security best practices by validating the key's format and handling it via temporary configuration files rather than command-line arguments.\n- [EXTERNAL_DOWNLOADS]: The skill retrieves research data from api.crawlora.net. As this is the vendor's own infrastructure, this communication is consistent with the skill's stated purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes card listing data from various marketplaces. While this content is technically untrusted, the risk is minimized by the skill's limited capabilities:\n
  • Ingestion points: JSON responses from the Crawlora API (market listings, auction data).\n
  • Boundary markers: The skill instructions emphasize normalization and reporting observed ranges, acting as a functional boundary for processing the data.\n
  • Capability inventory: The skill is limited to making GET requests via a hardened bash script; it has no file-writing or arbitrary command execution capabilities.\n
  • Sanitization: The skill relies on the structured nature of the API response and specific search parameters to limit the input surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — collectibles-market-research