local-business-reputation-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted business reviews and profile data from external platforms (Yelp, BBB, Trustpilot, OpenTable), which could theoretically contain malicious prompts intended to influence agent behavior.
- Ingestion points: Untrusted data enters the agent context through the output of
scripts/crawlora.shwhen fetching content from the platforms defined inreference/endpoints.md. - Boundary markers: Present.
SKILL.mdcontains instructions to maintain explicit source boundaries, preserve platform-specific rating scales and moderation labels, and quote only necessary excerpts. - Capability inventory:
scripts/crawlora.shperforms network operations usingcurland usesjqto process JSON output. - Sanitization: Present. The
scripts/crawlora.shscript enforces URL encoding for query parameters and validates requested paths against a strict whitelist and regex set.
Audit Metadata