website-monitoring
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a bash script
scripts/crawlora.shto perform API calls. The script is designed with security in mind, usingmktempto handle secrets securely and implementing strict regex-based allow-listing for API routes to prevent unauthorized command execution or path traversal.- [EXTERNAL_DOWNLOADS]: The skill makes requests toapi.crawlora.net. This is a vendor-owned resource used for the skill's primary functionality of managing website change monitors.- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the Crawlora API regarding monitor status and check history. - Ingestion points: API response data fetched via
scripts/crawlora.sh. - Boundary markers: The documentation specifies that data is returned as normalized JSON.
- Capability inventory: The skill can execute the provided bash script to perform authenticated network operations, which are constrained by the script's validation logic.
- Sanitization: The helper script validates all paths and parameters, specifically preventing shell injection and local file reading through curl parameters by rejecting specific characters like '@' in query arguments.
Audit Metadata