journalist-media-research
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a bundled shell script
scripts/crawlora.shto perform API requests. The script implements multiple layers of security: - It validates the
CRAWLORA_API_KEYformat to prevent injection attacks. - It uses a temporary, restricted-permission configuration file to pass the API key to
curl, preventing it from appearing in process lists. - It strictly whitelists allowed HTTP methods and API paths, preventing the agent from calling unauthorized endpoints.
- It implements safe handling of parameters to prevent local file disclosure by rejecting the
@character in query strings and usingstdinfor POST bodies. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests data from external sources including Bing search results and web page content via the
/web/scrapeendpoint. - Ingestion points: Data enters the context through
scripts/crawlora.shvia the/bing/search,/bing/news, and/web/scraperoutes. - Boundary markers: The instructions include workflow steps for manual verification, requirement to cite evidence, and distinguishing between verified and unverified coverage.
- Capability inventory: The skill uses
curlwithin the shell script to perform network operations to the vendor's API base URL. - Sanitization: The shell script performs strict path and method validation before execution. The final output is structured as a table or CSV for user review.
Audit Metadata