twitch-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a helper script (
scripts/crawlora.sh) to executecurlcommands. The script includes significant defensive measures, such as a strict route whitelist, a character-level charset check for API keys, and the use of--data-urlencodeto prevent argument injection into the query string. - [EXTERNAL_DOWNLOADS]: The skill fetches Twitch data from
api.crawlora.net. As identified in the author context, this is a legitimate resource belonging to the skill's vendor (crawlora-org). - [CREDENTIALS_UNSAFE]: The skill requires a
CRAWLORA_API_KEYfor operation. The implementation follows security best practices by reading this secret from an environment variable and passing it tocurlvia a temporary configuration file with restricted permissions (chmod 600), ensuring the key is not exposed in the process tree or shell history. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external content from Twitch, such as stream titles and chat messages, which are controlled by third parties. While this introduces an ingestion surface for indirect prompt injection, the skill's capabilities are limited to retrieval, and the data is returned as structured JSON, reducing the risk of unintended agent behavior.
Audit Metadata