supplier-sourcing-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a bash helper
scripts/crawlora.shto interface with the Crawlora API. The script implements robust security measures, including restricted API key character sets to prevent injection into configuration files and strict path/method whitelisting that limits the agent's interaction to verified API routes. - [CREDENTIALS_UNSAFE]: The skill uses an environment variable
CRAWLORA_API_KEYprovided by the user. The helper script manages this safely by using a temporarycurlconfiguration file with restricted permissions (chmod 600) and ensures the key is not passed as a command-line argument, preventing exposure in process listings or command history. - [DATA_EXFILTRATION]: The bash helper prevents local file disclosure and exfiltration by explicitly rejecting the
@character in query parameters and using standard input for request bodies, which preventscurlfrom interpreting user-supplied strings as local file paths. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from web searches and company reports.
- Ingestion points: Bing search results, ImportYeti company reports, and scraped web content from official supplier websites as defined in
SKILL.mdandreference/endpoints.md. - Boundary markers: Instructions explicitly direct the agent to "separate claimed capabilities/certifications from independently verified facts," providing a logical framework for evaluating untrusted input.
- Capability inventory: Shell execution is strictly limited to the
scripts/crawlora.shAPI helper; the skill lacks high-risk capabilities such as file system writes (except for a temporary credentials file) or dynamic code evaluation. - Sanitization: The
crawlora.shscript sanitizes all inputs to prevent path traversal and preventscurlfrom accessing local files during API interactions.
Audit Metadata