crowdfunding-campaign-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a custom shell script scripts/crawlora.sh to communicate with the Crawlora API. The script includes robust security controls: it validates the CRAWLORA_API_KEY format to prevent injection, restricts API paths to an allowed list, and uses a temporary curl configuration file with chmod 600 to handle credentials securely without exposing them in command-line arguments.
  • [DATA_EXPOSURE]: The helper script prevents local file disclosure by explicitly rejecting the @ character in query parameters, which prevents curl from reading local files as input.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Kickstarter and web scraping. The instructions include guidelines for the agent to use short excerpts and attribute findings as reports, which helps maintain clear boundaries between external data and agent reasoning. Ingestion points: Data is fetched via scripts/crawlora.sh from api.crawlora.net (/kickstarter/* and /web/scrape routes). Boundary markers: Instructions specify citing short excerpts and maintaining chronological context. Capability inventory: The skill has network access via the crawlora.sh script. Sanitization: Instructions mandate specific parsing rules for update dates and comment themes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — crowdfunding-campaign-research