google-trends-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a bundled bash script
scripts/crawlora.shto perform API requests. This script implements several security controls, including character-set validation for the API key to prevent configuration injection and a strict allow-list of authorized API paths to ensure the agent only accesses intended Trends endpoints. - [DATA_EXFILTRATION]: Sensitive API keys are managed securely. The script writes the
CRAWLORA_API_KEYto a temporary curl configuration file with restricted read/write permissions (chmod 600) and uses a shell trap to ensure the file is deleted immediately after the request completes. Network communication is restricted to the vendor's official API atapi.crawlora.net. - [INDIRECT_PROMPT_INJECTION]: The skill processes external search data from Google Trends. The implementation mitigates common injection risks by blocking the
@character in query parameters and streaming POST bodies via stdin, which prevents the underlyingcurlcommand from being tricked into reading or uploading local system files.
Audit Metadata