sec-filings-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a local helper script, scripts/crawlora.sh, to perform API requests. This script includes significant security hardening, such as validating the API key format to prevent header injection and using a temporary configuration file to keep credentials out of the process list.\n- [EXTERNAL_DOWNLOADS]: The skill communicates with the vendor's API at api.crawlora.net and includes a generic web scraping tool (/web/scrape) for retrieving content from external URLs.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from SEC filings and web pages, which could theoretically contain malicious instructions. This is an inherent risk factor for skills designed to summarize or analyze third-party content.\n
  • Ingestion points: Output from the Crawlora API via scripts/crawlora.sh, specifically filing sections and scraped web content.\n
  • Boundary markers: The skill provides high-level instructions to differentiate between facts and interpretations but lacks technical delimiters for raw data input.\n
  • Capability inventory: The skill allows network communication via the Crawlora helper script and file system access as permitted by the agent environment.\n
  • Sanitization: There is no evidence of automated content sanitization beyond the script's path and argument validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — sec-filings-research