kohls-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on a bash helper script (scripts/crawlora.sh) to interface with the Crawlora API. The script demonstrates several security best practices: it validates the CRAWLORA_API_KEY format to prevent shell injection via environment variables, uses an allow-list for API paths, strictly permits only GET requests, employs temporary curl configuration files to pass the API key (preventing exposure in process lists), and uses --data-urlencode to safely handle user-provided query parameters.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the external Crawlora API, which could theoretically contain malicious instructions.
  • Ingestion points: The skill fetches category data, reviews, and store listings from api.crawlora.net as seen in scripts/crawlora.sh.
  • Boundary markers: No specific delimiters or instructions to ignore embedded content are used when presenting API output to the agent.
  • Capability inventory: The skill performs network requests and local command execution via curl.
  • Sanitization: Outgoing parameters are properly encoded, but the incoming JSON response is parsed directly by the agent without further sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — kohls-research