techstack-prospecting

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a bundled bash script (scripts/crawlora.sh) to interact with the vendor API. The script implements multiple security controls, including a fixed base URL, a strict whitelist of allowed API paths, and validation of HTTP methods. It further sanitizes path inputs to prevent traversal and blocks the use of characters like '@' in query arguments, mitigating the risk of local file disclosure through curl.
  • [CREDENTIALS_UNSAFE]: The skill handles the required CRAWLORA_API_KEY following security best practices. The script validates the key's format and uses a temporary curl configuration file with restricted filesystem permissions (chmod 600) to provide the API key as a header, ensuring the secret is not exposed in the system's process listings or shell history.
  • [INDIRECT_PROMPT_INJECTION]: The skill's functionality involves scraping and analyzing data from external websites, which introduces a potential surface for indirect prompt injection attacks.
  • Ingestion points: External website content is retrieved through the /web/scrape and /web/techstack endpoints as described in SKILL.md.
  • Boundary markers: The prompt instructions do not specify the use of delimiters to isolate the untrusted web data from the agent's core instructions.
  • Capability inventory: The skill maintains network access via the scripts/crawlora.sh utility calling the Crawlora API.
  • Sanitization: There is no explicit sanitization step described for the markdown content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — techstack-prospecting