tiktok-trend-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external TikTok feeds and the Creative Center via the Crawlora API. This creates a potential surface for indirect prompt injection, where malicious text within video metadata or descriptions could attempt to influence the agent's behavior.
- Ingestion points: Data is fetched from api.crawlora.net via scripts/crawlora.sh as documented in SKILL.md.
- Boundary markers: The instructions do not define specific structural delimiters (such as XML tags or dedicated headers) for the ingested data within the prompt context, relying on the agent to distinguish signal from interpretation.
- Capability inventory: The skill possesses network access via curl in scripts/crawlora.sh and can read local files within its directory.
- Sanitization: The crawlora.sh helper script implements significant security controls, including whitelisting specific API routes, validating API key character sets to prevent shell injection, and preventing curl from accessing local files through query parameters by rejecting the '@' character.
Audit Metadata