housing-market-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a bundled shell script (scripts/crawlora.sh) to interact with its API. The script is professionally hardened with multiple security controls:
  • Strict path validation using anchored regular expressions and case-switch patterns ensures only documented endpoints can be called.
  • Protection against Local File Disclosure (LFD) is implemented by explicitly rejecting the @ character in query arguments and using --data-binary @- with stdin for POST bodies, preventing curl from reading local files.
  • Secure credential handling via a temporary curl configuration file prevents the CRAWLORA_API_KEY from appearing in system process listings.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to api.crawlora.net to retrieve housing dataset information. This domain is the official infrastructure for the skill's vendor (crawlora-org).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from housing market datasets which represents a potential injection surface.
  • Ingestion points: External JSON data is retrieved from api.crawlora.net via the scripts/crawlora.sh helper.
  • Boundary markers: The SKILL.md file provides clear instructions on data interpretation, such as preserving nulls and disclosing assumptions, which assists the agent in distinguishing data from instructions.
  • Capability inventory: The skill can execute local shell commands (scripts/crawlora.sh) and perform network operations via curl.
  • Sanitization: The helper script provides strong input sanitization for arguments, though the final JSON payload from the API is processed directly by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — housing-market-research