local-competitive-landscape
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements business logic for competitive landscape analysis using the Crawlora API to compare data across Google Maps, Apple Maps, and Yelp.
- [COMMAND_EXECUTION]: The skill uses a local helper script
scripts/crawlora.shto perform network requests. The script includes significant defensive measures: API key format validation to prevent injection, a strict whitelist of allowed URL paths and HTTP methods, and protection against local file disclosure by rejecting the@character in query arguments. - [DATA_EXFILTRATION]: Network operations are restricted to the vendor's official API domain (
api.crawlora.net). Secret handling for theCRAWLORA_API_KEYis performed via temporary configuration files with restricted permissions to avoid exposure in process lists or logs. - [INDIRECT_PROMPT_INJECTION]: The skill processes business data from external providers.
- Ingestion points: Business data is fetched via
scripts/crawlora.shfrom Google, Apple, and Yelp search/detail endpoints. - Boundary markers: Absent; the instructions do not explicitly warn the agent to ignore instructions embedded in business names or categories.
- Capability inventory: The agent is limited to using the provided helper script for API calls; it lacks privileges for arbitrary shell execution or sensitive file system modifications.
- Sanitization: Absent; the data is used directly for matrix and comparison generation.
Audit Metadata