earnings-event-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a bundled bash script scripts/crawlora.sh to perform network requests to api.crawlora.net. The script implements comprehensive security controls:
  • It enforces a hardcoded base URL, preventing redirection to unauthorized hosts.
  • It uses a whitelist and anchored regular expressions to restrict execution to specific API paths.
  • It utilizes curl -G --data-urlencode to ensure all user-supplied query parameters are safely encoded, preventing command injection.
  • It explicitly blocks the @ character in arguments to prevent curl from reading local files.
  • [CREDENTIALS_UNSAFE]: The skill manages the CRAWLORA_API_KEY through environment variables rather than hardcoding. The helper script handles the key securely by writing it to a temporary curl configuration file with restricted permissions (chmod 600) and ensures the file's removal via a trap command, preventing the key from appearing in process listings.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Yahoo Finance and SEC filings, which serves as a potential ingestion point for untrusted content. The implementation includes the following components:
  • Ingestion points: Data is retrieved from external endpoints via scripts/crawlora.sh.
  • Boundary markers: The instructions guide the agent to "label it unknown rather than inferring" and to "Keep management claims, reported facts, estimates, calculations, and interpretation separate."
  • Capability inventory: The skill's primary capability is performing GET requests to retrieve structured financial data; no dangerous write or execution capabilities are exposed to the ingested data.
  • Sanitization: While the script returns raw JSON, the instructions mandate verification against primary SEC documents and specific fiscal period matching to ensure data integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — earnings-event-research