kohls-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on a bash helper script (scripts/crawlora.sh) to interface with the Crawlora API. The script demonstrates several security best practices: it validates the CRAWLORA_API_KEY format to prevent shell injection via environment variables, uses an allow-list for API paths, strictly permits only GET requests, employs temporary curl configuration files to pass the API key (preventing exposure in process lists), and uses --data-urlencode to safely handle user-provided query parameters.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the external Crawlora API, which could theoretically contain malicious instructions.
- Ingestion points: The skill fetches category data, reviews, and store listings from api.crawlora.net as seen in scripts/crawlora.sh.
- Boundary markers: No specific delimiters or instructions to ignore embedded content are used when presenting API output to the agent.
- Capability inventory: The skill performs network requests and local command execution via curl.
- Sanitization: Outgoing parameters are properly encoded, but the incoming JSON response is parsed directly by the agent without further sanitization.
Audit Metadata