travel-accommodation-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill interacts with the Crawlora API (crawlora.net) using a dedicated helper script. The script, scripts/crawlora.sh, uses set -euo pipefail and provides robust validation for all inputs.
  • [SAFE]: API keys are handled securely through environment variables and temporary curl configuration files. The script validates the key format to prevent injection attacks and ensures the sensitive data is not exposed in the process list.
  • [COMMAND_EXECUTION]: The helper script invokes curl to perform network operations. Security is maintained by strictly whitelisting allowed API routes and HTTP methods, and by using --data-urlencode to sanitize query parameters.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes property and review data from travel platforms which are external to the agent.
  • Ingestion points: Search results and property details retrieved from Agoda, Airbnb, Hotels.com, and Trip.com via scripts/crawlora.sh.
  • Boundary markers: None explicitly defined in the prompts, though the agent is instructed to return structured JSON.
  • Capability inventory: Execution of scripts/crawlora.sh for API requests and jq for result filtering.
  • Sanitization: Input parameters are encoded and the script enforces a strict catalog of allowed API endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — travel-accommodation-research