startup-acquisition-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a local bash script scripts/crawlora.sh to communicate with the Crawlora API. The script implements defensive programming practices, including API key format validation and path segment filtering to prevent directory traversal.\n- [EXTERNAL_DOWNLOADS]: The skill performs network requests to the official Crawlora API at api.crawlora.net to retrieve startup metrics and uses a scraping endpoint to fetch content from third-party websites. These operations are directed at the vendor's own infrastructure.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize untrusted data from external websites and marketplace listings, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: Web content retrieved via the /web/scrape endpoint and business descriptions from the TrustMRR dataset are processed by the agent (SKILL.md, Step 6).\n
  • Boundary markers: No explicit delimiters are used to wrap external content in the provided instructions to differentiate it from system instructions.\n
  • Capability inventory: The agent can execute scripts/crawlora.sh, which performs network operations (GET/POST) but does not have file-system write access beyond temporary configuration files.\n
  • Sanitization: While the shell script sanitizes inputs sent to the API, there is no evidence of automated sanitization or filtering for the data returned from external websites before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — startup-acquisition-research