podcast-guest-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external podcast search results and scraped web pages.\n
  • Ingestion points: SKILL.md and reference/endpoints.md describe fetching content from external podcast directories (Apple, Spotify) and show websites using the /web/scrape endpoint.\n
  • Boundary markers: The instructions do not mandate specific delimiters or "ignore instructions" warnings for the agent when processing this external content.\n
  • Capability inventory: The skill's capabilities are restricted to network requests to the api.crawlora.net domain via scripts/crawlora.sh. It does not have general file system access or arbitrary command execution capabilities.\n
  • Sanitization: There is no explicit sanitization step for the external content before it is processed by the agent.\n- [COMMAND_EXECUTION]: The skill utilizes a local bash script scripts/crawlora.sh to execute API requests using curl.\n
  • The script implements significant security controls, including strict alphanumeric validation for API keys, a whitelist for allowed API paths, and a check to prevent local file disclosure by rejecting the @ character in query parameters.\n
  • It further secures the API key by using a temporary configuration file with restricted permissions (chmod 600) to pass the header to curl, preventing the key from appearing in the system's process list.\n- [EXTERNAL_DOWNLOADS]: The skill communicates with the Crawlora API at api.crawlora.net to retrieve podcast and show metadata.\n
  • As this interaction is limited to the vendor's own infrastructure and is essential for the skill's stated purpose, it is documented as standard functional behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — podcast-guest-research