patents-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill retrieves patent information from the official Crawlora API at api.crawlora.net.
  • [COMMAND_EXECUTION]: The helper script scripts/crawlora.sh uses curl with proper security measures, including API key validation and the use of temporary config files to prevent credential exposure.
  • [DATA_EXFILTRATION]: The script explicitly blocks the use of the @ character in arguments, preventing curl from accidentally disclosing local files.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests data from external patent databases, it lacks capabilities that would allow this data to execute commands or write files on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — patents-research