gaming-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
scripts/crawlora.shto make API calls. The script employs multiple security layers including path whitelisting, parameter encoding, and restricted variable formats. It securely handles the API key via a temporary curl configuration file with restricted permissions (chmod 600), preventing exposure in the process tree. \n- [EXTERNAL_DOWNLOADS]: Communicates with the vendor's API atapi.crawlora.netto retrieve game data. \n- [INDIRECT_PROMPT_INJECTION]: The skill ingests content from game store pages and reviews which could theoretically contain malicious instructions. \n - Ingestion points: JSON data from
api.crawlora.netretrieved inscripts/crawlora.sh. \n - Boundary markers: None identified in the skill body. \n
- Capability inventory: The skill can perform network operations via
scripts/crawlora.sh. \n - Sanitization: Path validation and URL encoding are implemented in the helper script, though the final text content of game reviews is not filtered for potential injection patterns.
Audit Metadata