opensea-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill communicates with api.crawlora.net, which is the official API endpoint for the vendor (crawlora-org). This is the intended behavior for an NFT research skill.
  • [COMMAND_EXECUTION]: The skill uses a helper script scripts/crawlora.sh to execute curl commands. The script includes robust input validation, such as a regex-based route allowlist and checks to prevent local file disclosure via curl's @ syntax.
  • [SAFE]: The skill follows security best practices by storing the API key in a temporary, restricted-permission file during execution instead of passing it as a command-line argument.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — opensea-research