customer-feedback-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted customer feedback from external sources, creating an attack surface for indirect prompt injection where malicious instructions could be embedded in review data.
  • Ingestion points: Fetches content from platforms including the App Store, Google Play, and Reddit via the scripts/crawlora.sh utility.
  • Boundary markers: Instructions lack explicit delimiters to isolate processed review text from agent instructions.
  • Capability inventory: The skill executes a local bash script (scripts/crawlora.sh) that performs network operations.
  • Sanitization: The helper script implements robust input validation, including path whitelisting and URL-encoding of query parameters.
  • [COMMAND_EXECUTION]: The skill relies on a local script, scripts/crawlora.sh, which is implemented with defensive security practices, such as strict parameter validation and secure API key management using temporary restricted files.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves data from the vendor's official API at api.crawlora.net.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — customer-feedback-analysis