fiverr-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local bash helper script (scripts/crawlora.sh) to interact with the Crawlora API. The script features robust security controls, including protecting the API key from command-line disclosure via temporary curl configuration files and using strict route whitelisting to restrict API access to documented endpoints.
  • [EXTERNAL_DOWNLOADS]: The skill performs authenticated requests to the vendor's API at api.crawlora.net to fetch Fiverr gig and seller data.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Fiverr gig listings and seller profiles, representing a standard indirect prompt injection surface.
  • Ingestion points: External data enters the agent's context through API responses processed in scripts/crawlora.sh.
  • Boundary markers: The skill does not explicitly provide instructions or delimiters to isolate untrusted external content from the agent's primary instructions.
  • Capability inventory: The skill possesses capabilities for network operations to a specific vendor API and execution of a local script.
  • Sanitization: While the script validates input parameters, the retrieved content from Fiverr is passed as-is in JSON format without specific sanitization for embedded prompt instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — fiverr-research