short-term-rental-market-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a bundled bash script
scripts/crawlora.shto executecurlcommands for API interaction. - The script implements several security best practices, including whitelisting specific API routes to ensure least privilege access.
- It prevents local file disclosure attacks by explicitly rejecting the
@character in query parameters and using the--data-binary @-pattern with stdin for POST bodies, which preventscurlfrom interpreting values as file paths. - It protects the user's
CRAWLORA_API_KEYby writing it to a temporary configuration file with restricted permissions (600) and using the--configflag, ensuring the secret does not appear in process listings. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the Crawlora API (
api.crawlora.net), which serves as an attack surface for indirect prompt injection if the API response contains malicious instructions. - Ingestion points: API response data from the
datasets/airbnb-markets/*andairbnb/*endpoints. - Boundary markers: The skill does not explicitly define markers but provides structured instructions on how to interpret specific fields (e.g., distinguishing between counts and percentages).
- Capability inventory: The skill can execute network requests via
curland read/write files as part of its normal operation. - Sanitization: The
crawlora.shscript performs path and method validation before execution.
Audit Metadata