podcast-guest-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external podcast search results and scraped web pages.\n
- Ingestion points:
SKILL.mdandreference/endpoints.mddescribe fetching content from external podcast directories (Apple, Spotify) and show websites using the/web/scrapeendpoint.\n - Boundary markers: The instructions do not mandate specific delimiters or "ignore instructions" warnings for the agent when processing this external content.\n
- Capability inventory: The skill's capabilities are restricted to network requests to the
api.crawlora.netdomain viascripts/crawlora.sh. It does not have general file system access or arbitrary command execution capabilities.\n - Sanitization: There is no explicit sanitization step for the external content before it is processed by the agent.\n- [COMMAND_EXECUTION]: The skill utilizes a local bash script
scripts/crawlora.shto execute API requests usingcurl.\n - The script implements significant security controls, including strict alphanumeric validation for API keys, a whitelist for allowed API paths, and a check to prevent local file disclosure by rejecting the
@character in query parameters.\n - It further secures the API key by using a temporary configuration file with restricted permissions (
chmod 600) to pass the header tocurl, preventing the key from appearing in the system's process list.\n- [EXTERNAL_DOWNLOADS]: The skill communicates with the Crawlora API atapi.crawlora.netto retrieve podcast and show metadata.\n - As this interaction is limited to the vendor's own infrastructure and is essential for the skill's stated purpose, it is documented as standard functional behavior.
Audit Metadata