influencer-discovery

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a bundled shell script scripts/crawlora.sh to interact with the vendor's API. The script is highly secure, featuring robust validation of paths and API key formats, and it correctly uses a temporary file to pass credentials to curl to avoid exposing them in process listings.
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to the vendor's official API domain (api.crawlora.net). These connections are restricted by the script to a fixed base URL and a specific set of allowed API routes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes social media profile data (bios, nicknames, post content) from third-party platforms which could potentially contain malicious instructions.
  • Ingestion points: External data enters the agent context via the output of scripts/crawlora.sh after fetching profile and search data.
  • Boundary markers: The skill does not define explicit delimiters for social media content in its instructions.
  • Capability inventory: The skill's capabilities are limited to vendor API access and data processing; it lacks access to the local file system (beyond the temp file it manages) or the ability to execute arbitrary system commands.
  • Sanitization: The agent is instructed to extract specific metrics and identifiers (e.g., follower counts, engagement rates), which naturally limits the influence of free-text content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — influencer-discovery