dining-demand-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches restaurant discovery and availability data from
https://api.crawlora.net/api/v1. This is the vendor's official API endpoint for the skill. - [COMMAND_EXECUTION]: Uses
scripts/crawlora.shto communicate with the API. The script demonstrates high security maturity by implementing several protections: - Strict validation of the
CRAWLORA_API_KEYcharacter set to prevent shell injection. - A whitelist of authorized API paths to prevent access to unintended endpoints.
- Secure handling of the API key using a temporary file with restricted permissions (
chmod 600) and automatic cleanup viatrap. - Use of
--data-urlencodeto safely handle user-supplied query parameters. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data, specifically restaurant menus and diner reviews from OpenTable and Resy. This is a common surface for indirect prompt injection, though the risk is minimized by the skill's read-only research focus and the absence of executable capabilities applied to the retrieved data.
Audit Metadata