local-business-prospecting
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from arbitrary public business websites to qualify leads, which presents a surface for indirect prompt injection.
- Ingestion points: Web content fetched via the
/web/scrapeand/extractendpoints (documented inreference/endpoints.md). - Boundary markers: The skill instructions in
SKILL.mddo not include specific delimiters or guidelines to the agent to ignore instructions embedded within the scraped content. - Capability inventory: The agent can execute network requests to the vendor API and write information to CSV files.
- Sanitization: There is no evidence of sanitization or filtering of the external content before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill interacts with the Crawlora API at
api.crawlora.net. This is a vendor-owned resource used for its intended purpose of business prospecting. - [COMMAND_EXECUTION]: The skill utilizes a bundled bash script (
scripts/crawlora.sh) to interact with the API. The script implements several security best practices, including input validation, a path whitelist, and secure handling of API keys to prevent them from appearing in process listings or being exploited for local file disclosure.
Audit Metadata