journalist-media-research

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled shell script scripts/crawlora.sh to perform API requests. The script implements multiple layers of security:
  • It validates the CRAWLORA_API_KEY format to prevent injection attacks.
  • It uses a temporary, restricted-permission configuration file to pass the API key to curl, preventing it from appearing in process lists.
  • It strictly whitelists allowed HTTP methods and API paths, preventing the agent from calling unauthorized endpoints.
  • It implements safe handling of parameters to prevent local file disclosure by rejecting the @ character in query strings and using stdin for POST bodies.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests data from external sources including Bing search results and web page content via the /web/scrape endpoint.
  • Ingestion points: Data enters the context through scripts/crawlora.sh via the /bing/search, /bing/news, and /web/scrape routes.
  • Boundary markers: The instructions include workflow steps for manual verification, requirement to cite evidence, and distinguishing between verified and unverified coverage.
  • Capability inventory: The skill uses curl within the shell script to perform network operations to the vendor's API base URL.
  • Sanitization: The shell script performs strict path and method validation before execution. The final output is structured as a table or CSV for user review.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 12:36 PM
Security Audit — agent-trust-hub — journalist-media-research