local-business-prospecting

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from arbitrary public business websites to qualify leads, which presents a surface for indirect prompt injection.
  • Ingestion points: Web content fetched via the /web/scrape and /extract endpoints (documented in reference/endpoints.md).
  • Boundary markers: The skill instructions in SKILL.md do not include specific delimiters or guidelines to the agent to ignore instructions embedded within the scraped content.
  • Capability inventory: The agent can execute network requests to the vendor API and write information to CSV files.
  • Sanitization: There is no evidence of sanitization or filtering of the external content before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the Crawlora API at api.crawlora.net. This is a vendor-owned resource used for its intended purpose of business prospecting.
  • [COMMAND_EXECUTION]: The skill utilizes a bundled bash script (scripts/crawlora.sh) to interact with the API. The script implements several security best practices, including input validation, a path whitelist, and secure handling of API keys to prevent them from appearing in process listings or being exploited for local file disclosure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — local-business-prospecting