news-media-research

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes articles and metadata from external news publishers, creating a standard surface for indirect prompt injection. This is an inherent risk of the skill's primary function and is mitigated by the agent's internal safety guardrails and the skill's focus on structured data retrieval. 1. Ingestion points: scripts/crawlora.sh fetches JSON article data from the Crawlora API. 2. Boundary markers: Not explicitly defined in instructions. 3. Capability inventory: The skill performs shell execution of curl via a local script. 4. Sanitization: The helper script enforces path allowlisting and data encoding before transmission.
  • [COMMAND_EXECUTION]: The helper script scripts/crawlora.sh is highly defensive, employing a rigid route allowlist and strict path validation (rejecting characters like ?, #, %, and ..) to prevent command smuggling or unauthorized API access.
  • [DATA_EXPOSURE]: The skill manages vendor-specific API credentials using environment variables. The helper script prevents exposure in system process lists by writing the key to a temporary curl configuration file with restricted permissions (chmod 600) and ensuring its deletion via an EXIT trap.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 12:37 PM
Security Audit — agent-trust-hub — news-media-research