entertainment-discovery-research

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a bash script scripts/crawlora.sh to interface with the Crawlora API. The script is well-hardened, featuring validation for the API key format, a hardcoded base URL, a strict whitelist of allowed paths, and protection against curl file upload parameters.
  • [CREDENTIALS_UNSAFE]: Use of the CRAWLORA_API_KEY environment variable is managed securely. The script writes the key to a temporary file with restricted permissions (chmod 600) and uses the curl --config flag to prevent the key from appearing in the system's process list.
  • [EXTERNAL_DOWNLOADS]: The skill performs GET requests to api.crawlora.net to retrieve entertainment metadata. This behavior is expected and aligns with the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted data from entertainment sites (IMDb, Rotten Tomatoes, etc.) via the scripts/crawlora.sh script. While no sanitization is performed on the raw JSON output and no prompt boundaries are explicitly defined in the script, the risk is minimized by the highly structured nature of the data and the script's restriction to specific, non-executable metadata endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:02 AM
Security Audit — agent-trust-hub — entertainment-discovery-research