techstack-prospecting
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a bundled bash script (
scripts/crawlora.sh) to interact with the vendor API. The script implements multiple security controls, including a fixed base URL, a strict whitelist of allowed API paths, and validation of HTTP methods. It further sanitizes path inputs to prevent traversal and blocks the use of characters like '@' in query arguments, mitigating the risk of local file disclosure through curl. - [CREDENTIALS_UNSAFE]: The skill handles the required
CRAWLORA_API_KEYfollowing security best practices. The script validates the key's format and uses a temporary curl configuration file with restricted filesystem permissions (chmod 600) to provide the API key as a header, ensuring the secret is not exposed in the system's process listings or shell history. - [INDIRECT_PROMPT_INJECTION]: The skill's functionality involves scraping and analyzing data from external websites, which introduces a potential surface for indirect prompt injection attacks.
- Ingestion points: External website content is retrieved through the
/web/scrapeand/web/techstackendpoints as described inSKILL.md. - Boundary markers: The prompt instructions do not specify the use of delimiters to isolate the untrusted web data from the agent's core instructions.
- Capability inventory: The skill maintains network access via the
scripts/crawlora.shutility calling the Crawlora API. - Sanitization: There is no explicit sanitization step described for the markdown content retrieved from external sources before it is processed by the agent.
Audit Metadata