housing-market-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a bundled shell script (
scripts/crawlora.sh) to interact with its API. The script is professionally hardened with multiple security controls: - Strict path validation using anchored regular expressions and case-switch patterns ensures only documented endpoints can be called.
- Protection against Local File Disclosure (LFD) is implemented by explicitly rejecting the
@character in query arguments and using--data-binary @-with stdin for POST bodies, preventingcurlfrom reading local files. - Secure credential handling via a temporary
curlconfiguration file prevents theCRAWLORA_API_KEYfrom appearing in system process listings. - [EXTERNAL_DOWNLOADS]: The skill performs network requests to
api.crawlora.netto retrieve housing dataset information. This domain is the official infrastructure for the skill's vendor (crawlora-org). - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from housing market datasets which represents a potential injection surface.
- Ingestion points: External JSON data is retrieved from
api.crawlora.netvia thescripts/crawlora.shhelper. - Boundary markers: The
SKILL.mdfile provides clear instructions on data interpretation, such as preserving nulls and disclosing assumptions, which assists the agent in distinguishing data from instructions. - Capability inventory: The skill can execute local shell commands (
scripts/crawlora.sh) and perform network operations viacurl. - Sanitization: The helper script provides strong input sanitization for arguments, though the final JSON payload from the API is processed directly by the agent.
Audit Metadata