local-competitive-landscape

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements business logic for competitive landscape analysis using the Crawlora API to compare data across Google Maps, Apple Maps, and Yelp.
  • [COMMAND_EXECUTION]: The skill uses a local helper script scripts/crawlora.sh to perform network requests. The script includes significant defensive measures: API key format validation to prevent injection, a strict whitelist of allowed URL paths and HTTP methods, and protection against local file disclosure by rejecting the @ character in query arguments.
  • [DATA_EXFILTRATION]: Network operations are restricted to the vendor's official API domain (api.crawlora.net). Secret handling for the CRAWLORA_API_KEY is performed via temporary configuration files with restricted permissions to avoid exposure in process lists or logs.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes business data from external providers.
  • Ingestion points: Business data is fetched via scripts/crawlora.sh from Google, Apple, and Yelp search/detail endpoints.
  • Boundary markers: Absent; the instructions do not explicitly warn the agent to ignore instructions embedded in business names or categories.
  • Capability inventory: The agent is limited to using the provided helper script for API calls; it lacks privileges for arbitrary shell execution or sensitive file system modifications.
  • Sanitization: Absent; the data is used directly for matrix and comparison generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — local-competitive-landscape