pet-services-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/crawlora.shexecutescurlto interact with the Crawlora API. It implements strict path validation using regular expressions and case statements to ensure only authorized endpoints (/rover/search,/rover/sitter/*, etc.) are accessed. It also sanitizes inputs by rejecting characters like@in query parameters to prevent local file disclosure via curl's built-in file reading features. - [EXTERNAL_DOWNLOADS]: The skill makes network requests to
api.crawlora.net. This is a standard vendor resource provided by the skill's author (crawlora-org) and does not represent an unknown or untrusted source. - [CREDENTIALS_UNSAFE]: The skill uses the
CRAWLORA_API_KEYenvironment variable for authentication. The helper script securely handles this secret by writing it to a temporary file with restricted permissions (chmod 600) and passing it to thecurlprocess via a configuration file, which prevents the API key from appearing in the system's process list or command history. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and display public data from Rover sitter and trainer profiles. While this data originates from an external source, the skill limits the risk by using a hardened script that constrains the interaction to specific, read-only API routes and processes the results as structured JSON.
Audit Metadata