news-briefing-research

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices for external API interaction.
  • [CREDENTIALS_SAFE]: The scripts/crawlora.sh script correctly instructs users to set an environment variable (CRAWLORA_API_KEY) rather than hardcoding secrets. It also uses a temporary curl config file (mktemp) with restricted permissions (chmod 600) to pass the key, preventing the secret from appearing in process lists (a common security risk with -H "x-api-key: ...").
  • [COMMAND_EXECUTION]: While the script executes curl, it implements comprehensive shell security: set -euo pipefail for error handling, strict validation of the CRAWLORA_API_KEY format (alphanumeric and safe symbols only), and umask 077 for temporary file security.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with api.crawlora.net. This is the official API endpoint for the skill's vendor (crawlora-org), representing normal and expected functionality for a news research tool.
  • [OBFUSCATION]: No obfuscated URLs, encoded payloads, or hidden character attacks were detected. The scripts are written in plain, readable Bash and Markdown.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to clearly separate reported news from AI inference and to label unverified allegations, which helps mitigate risks associated with processing untrusted external news data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:02 AM
Security Audit — agent-trust-hub — news-briefing-research