crypto-market-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill communicates with
api.crawlora.netto retrieve market data. This is the intended functionality and uses the vendor's official API infrastructure. - [COMMAND_EXECUTION]: The skill utilizes
scripts/crawlora.shto perform network requests. The script implementation is secure, using strict input validation to prevent path traversal and shell injection, and it avoids exposing API keys in the process command line by using a temporarycurlconfiguration file with restricted permissions. - [INDIRECT_PROMPT_INJECTION]: The skill processes external market data and news articles which could theoretically contain instructions intended for the agent.
- Ingestion points: Results from
scripts/crawlora.shcalls to CoinGecko endpoints, specifically news and coin profile data. - Boundary markers: Absent; the agent receives the raw JSON output from the API.
- Capability inventory: The skill is limited to running
scripts/crawlora.sh, which only performs GET requests to a hardcoded base URL. - Sanitization: The script sanitizes outgoing query parameters using
curl's--data-urlencodeflag, but does not filter the content of the returned API payload.
Audit Metadata