software-vendor-shortlisting

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a local shell script scripts/crawlora.sh to interface with the Crawlora API. The script includes security best practices, such as validating API key formats and using temporary configuration files to prevent credential exposure in process listings. It also explicitly blocks the use of the @ character in query parameters to prevent local file disclosure via curl.
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes untrusted data from external sources, including vendor websites and third-party product reviews.
  • Ingestion points: web/scrape, capterra/product/reviews, and producthunt/search endpoints called via scripts/crawlora.sh (as documented in SKILL.md).
  • Boundary markers: Absent. The instructions do not specify using delimiters or "ignore instructions" warnings when handling the scraped content.
  • Capability inventory: The skill performs network operations via curl within the scripts/crawlora.sh helper.
  • Sanitization: The helper script performs input validation on paths and query parameters, but no sanitization or filtering is applied to the content of the scraped pages or reviews before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — software-vendor-shortlisting