software-vendor-shortlisting
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a local shell script
scripts/crawlora.shto interface with the Crawlora API. The script includes security best practices, such as validating API key formats and using temporary configuration files to prevent credential exposure in process listings. It also explicitly blocks the use of the@character in query parameters to prevent local file disclosure via curl. - [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes untrusted data from external sources, including vendor websites and third-party product reviews.
- Ingestion points:
web/scrape,capterra/product/reviews, andproducthunt/searchendpoints called viascripts/crawlora.sh(as documented inSKILL.md). - Boundary markers: Absent. The instructions do not specify using delimiters or "ignore instructions" warnings when handling the scraped content.
- Capability inventory: The skill performs network operations via
curlwithin thescripts/crawlora.shhelper. - Sanitization: The helper script performs input validation on paths and query parameters, but no sanitization or filtering is applied to the content of the scraped pages or reviews before they are processed by the agent.
Audit Metadata