event-venue-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a local bash script (scripts/crawlora.sh) to perform API requests. The script implements defensive coding practices, including error handling via set -euo pipefail and strict validation of the CRAWLORA_API_KEY format to prevent injection attacks.
- [EXTERNAL_DOWNLOADS]: The skill fetches event and venue data from the vendor's official API at https://api.crawlora.net/api/v1. The script uses curl with a temporary configuration file created via mktemp to securely pass API keys in request headers, ensuring they do not appear in process logs or environment dumps.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external providers (Ticketmaster and TicketWeb) which could contain adversarial content. However, the skill's functionality is limited to read-only information retrieval (GET requests), and the communication script includes sanitization logic that rejects the @ character in query arguments to prevent unauthorized file access via curl.
Audit Metadata