news-briefing-research
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows security best practices for external API interaction.
- [CREDENTIALS_SAFE]: The
scripts/crawlora.shscript correctly instructs users to set an environment variable (CRAWLORA_API_KEY) rather than hardcoding secrets. It also uses a temporarycurlconfig file (mktemp) with restricted permissions (chmod 600) to pass the key, preventing the secret from appearing in process lists (a common security risk with-H "x-api-key: ..."). - [COMMAND_EXECUTION]: While the script executes
curl, it implements comprehensive shell security:set -euo pipefailfor error handling, strict validation of theCRAWLORA_API_KEYformat (alphanumeric and safe symbols only), andumask 077for temporary file security. - [EXTERNAL_DOWNLOADS]: The skill communicates with
api.crawlora.net. This is the official API endpoint for the skill's vendor (crawlora-org), representing normal and expected functionality for a news research tool. - [OBFUSCATION]: No obfuscated URLs, encoded payloads, or hidden character attacks were detected. The scripts are written in plain, readable Bash and Markdown.
- [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to clearly separate reported news from AI inference and to label unverified allegations, which helps mitigate risks associated with processing untrusted external news data.
Audit Metadata