sports-betting-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a local helper script, scripts/crawlora.sh, which is designed with strong security controls. It enforces an allowlist of permitted API paths and uses --data-urlencode to prevent command injection through user-supplied parameters.
  • [EXTERNAL_DOWNLOADS]: The skill connects to the Crawlora API (api.crawlora.net) to fetch sports data. This service is owned by the skill's author, crawlora-org, and is used according to its documented purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from sports betting and scoring websites.
  • Ingestion points: Data is retrieved via scripts/crawlora.sh and piped as JSON to the agent.
  • Boundary markers: The instructions tell the agent to keep odds and market data separate from its own predictions and timestamps.
  • Capability inventory: The skill can execute local scripts and use curl for network access.
  • Sanitization: All API requests are restricted to a specific path allowlist and all parameters are URL-encoded to ensure data integrity.
  • [SAFE]: The skill follows security best practices for handling API keys by using a temporary configuration file with restricted file permissions (600) and preventing the secret from appearing in process command lines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — sports-betting-research