developer-oss-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches GitHub and Chrome Web Store metadata from the Crawlora API (api.crawlora.net). This targets the vendor's own infrastructure for the skill's primary functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from third-party sources including GitHub repository descriptions, READMEs, and Chrome Web Store reviews. This content is not controlled by the skill author and may contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Data retrieved from GitHub and Chrome Web Store endpoints via the Crawlora API (e.g., referenced in reference/endpoints.md).
  • Boundary markers: No explicit delimiters or instructions are used to separate fetched external data from the agent's system instructions.
  • Capability inventory: The skill possesses network read capabilities (curl). It does not have file-write or arbitrary code execution capabilities.
  • Sanitization: Input parameters are sanitized in the shell script (scripts/crawlora.sh) to prevent command injection, but the retrieved JSON content is not filtered for potential prompt injection patterns before being processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — developer-oss-research