entertainment-discovery-research
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a bash script
scripts/crawlora.shto interface with the Crawlora API. The script is well-hardened, featuring validation for the API key format, a hardcoded base URL, a strict whitelist of allowed paths, and protection againstcurlfile upload parameters. - [CREDENTIALS_UNSAFE]: Use of the
CRAWLORA_API_KEYenvironment variable is managed securely. The script writes the key to a temporary file with restricted permissions (chmod 600) and uses thecurl --configflag to prevent the key from appearing in the system's process list. - [EXTERNAL_DOWNLOADS]: The skill performs
GETrequests toapi.crawlora.netto retrieve entertainment metadata. This behavior is expected and aligns with the skill's stated purpose. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted data from entertainment sites (IMDb, Rotten Tomatoes, etc.) via the
scripts/crawlora.shscript. While no sanitization is performed on the raw JSON output and no prompt boundaries are explicitly defined in the script, the risk is minimized by the highly structured nature of the data and the script's restriction to specific, non-executable metadata endpoints.
Audit Metadata