local-business-reputation-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted business reviews and profile data from external platforms (Yelp, BBB, Trustpilot, OpenTable), which could theoretically contain malicious prompts intended to influence agent behavior.
  • Ingestion points: Untrusted data enters the agent context through the output of scripts/crawlora.sh when fetching content from the platforms defined in reference/endpoints.md.
  • Boundary markers: Present. SKILL.md contains instructions to maintain explicit source boundaries, preserve platform-specific rating scales and moderation labels, and quote only necessary excerpts.
  • Capability inventory: scripts/crawlora.sh performs network operations using curl and uses jq to process JSON output.
  • Sanitization: Present. The scripts/crawlora.sh script enforces URL encoding for query parameters and validates requested paths against a strict whitelist and regex set.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — local-business-reputation-research