event-venue-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a local bash script (scripts/crawlora.sh) to perform API requests. The script implements defensive coding practices, including error handling via set -euo pipefail and strict validation of the CRAWLORA_API_KEY format to prevent injection attacks.
  • [EXTERNAL_DOWNLOADS]: The skill fetches event and venue data from the vendor's official API at https://api.crawlora.net/api/v1. The script uses curl with a temporary configuration file created via mktemp to securely pass API keys in request headers, ensuring they do not appear in process logs or environment dumps.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external providers (Ticketmaster and TicketWeb) which could contain adversarial content. However, the skill's functionality is limited to read-only information retrieval (GET requests), and the communication script includes sanitization logic that rejects the @ character in query arguments to prevent unauthorized file access via curl.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — event-venue-research