podcast-discovery-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/crawlora.shexecutescurlto perform API requests. It implements strict validation for theCRAWLORA_API_KEYto prevent shell injection and uses anchored regular expressions to whitelist specific API routes, preventing unauthorized path traversal or access to unintended endpoints. The API key is securely passed tocurlusing a temporary configuration file with restricted permissions. - [EXTERNAL_DOWNLOADS]: The skill fetches podcast metadata from the vendor's official API at
api.crawlora.net. These operations are consistent with the skill's primary purpose of podcast discovery and research. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted podcast metadata (such as show descriptions and episode notes) from Apple and Spotify via the Crawlora API.
- Ingestion points: Data retrieved from
scripts/crawlora.shduring show and episode discovery. - Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded instructions within the fetched metadata.
- Capability inventory: The agent can perform subsequent network requests and file operations based on potentially malicious content found in the metadata.
- Sanitization: No content sanitization or validation is applied to the ingested text before it is processed by the agent.
Audit Metadata