google-trends-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a bundled bash script scripts/crawlora.sh to perform API requests. This script implements several security controls, including character-set validation for the API key to prevent configuration injection and a strict allow-list of authorized API paths to ensure the agent only accesses intended Trends endpoints.
  • [DATA_EXFILTRATION]: Sensitive API keys are managed securely. The script writes the CRAWLORA_API_KEY to a temporary curl configuration file with restricted read/write permissions (chmod 600) and uses a shell trap to ensure the file is deleted immediately after the request completes. Network communication is restricted to the vendor's official API at api.crawlora.net.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external search data from Google Trends. The implementation mitigates common injection risks by blocking the @ character in query parameters and streaming POST bodies via stdin, which prevents the underlying curl command from being tricked into reading or uploading local system files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — google-trends-research