dining-demand-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches restaurant discovery and availability data from https://api.crawlora.net/api/v1. This is the vendor's official API endpoint for the skill.
  • [COMMAND_EXECUTION]: Uses scripts/crawlora.sh to communicate with the API. The script demonstrates high security maturity by implementing several protections:
  • Strict validation of the CRAWLORA_API_KEY character set to prevent shell injection.
  • A whitelist of authorized API paths to prevent access to unintended endpoints.
  • Secure handling of the API key using a temporary file with restricted permissions (chmod 600) and automatic cleanup via trap.
  • Use of --data-urlencode to safely handle user-supplied query parameters.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data, specifically restaurant menus and diner reviews from OpenTable and Resy. This is a common surface for indirect prompt injection, though the risk is minimized by the skill's read-only research focus and the absence of executable capabilities applied to the retrieved data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — dining-demand-research