lululemon-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The helper script scripts/crawlora.sh implements robust defensive measures:
  • Credential Security: The script validates the format of the CRAWLORA_API_KEY to prevent character injection and stores it in a temporary curl configuration file with restricted permissions (chmod 600). This prevents the key from appearing in process listings.
  • Path and Route Security: The script enforces a strict allow-list for API routes using case statements and anchored regular expressions, ensuring the agent cannot access unauthorized endpoints.
  • Injection and Disclosure Prevention: The script explicitly rejects query arguments containing the @ character to prevent curl from reading local files. For POST requests, it streams the body via stdin to avoid similar file-disclosure risks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes JSON data from an external API, creating a potential surface for indirect prompt injection if the API content were compromised.
  • Ingestion points: Data returned from the Crawlora API (api.crawlora.net) via the scripts/crawlora.sh script.
  • Boundary markers: None present in the instructions.
  • Capability inventory: The skill is restricted to making network requests to a specific set of Lululemon research endpoints.
  • Sanitization: The helper script sanitizes the request path and parameters, but the data returned by the API is passed to the agent as raw JSON without content-level sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — lululemon-research