competitor-intelligence

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the vendor's official API at api.crawlora.net to retrieve product, market, and traffic data. These operations are restricted to the vendor's infrastructure and are necessary for the skill's functionality.
  • [COMMAND_EXECUTION]: The skill executes a local shell script, scripts/crawlora.sh, which acts as a proxy for API calls. The script incorporates several security best practices: it protects the user's API key by passing it through a temporary configuration file instead of a command-line argument, preventing it from appearing in process logs; it implements a robust allowlist that restricts execution to specific, pre-authorized API paths and HTTP methods; and it prevents potential Local File Inclusion (LFI) by rejecting the @ symbol in query parameters, which would otherwise allow curl to read local files.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from various third-party websites (e.g., Trustpilot, Product Hunt, Capterra). 1. Ingestion points: Search results and scraped content are retrieved via the Crawlora API and passed to the agent for analysis. 2. Boundary markers: The prompt instructions require the agent to clearly separate official company claims, third-party feedback, and its own interpretations. 3. Capability inventory: The skill is designed for data analysis and reporting; it lacks autonomous capabilities to perform destructive actions or exfiltrate data to non-vendor domains. 4. Sanitization: The API script ensures that only structured JSON from authorized endpoints is processed, and it validates path parameters to prevent URL smuggling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — competitor-intelligence