lululemon-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The helper script
scripts/crawlora.shimplements robust defensive measures: - Credential Security: The script validates the format of the
CRAWLORA_API_KEYto prevent character injection and stores it in a temporary curl configuration file with restricted permissions (chmod 600). This prevents the key from appearing in process listings. - Path and Route Security: The script enforces a strict allow-list for API routes using
casestatements and anchored regular expressions, ensuring the agent cannot access unauthorized endpoints. - Injection and Disclosure Prevention: The script explicitly rejects query arguments containing the
@character to prevent curl from reading local files. For POST requests, it streams the body via stdin to avoid similar file-disclosure risks. - [INDIRECT_PROMPT_INJECTION]: The skill processes JSON data from an external API, creating a potential surface for indirect prompt injection if the API content were compromised.
- Ingestion points: Data returned from the Crawlora API (
api.crawlora.net) via thescripts/crawlora.shscript. - Boundary markers: None present in the instructions.
- Capability inventory: The skill is restricted to making network requests to a specific set of Lululemon research endpoints.
- Sanitization: The helper script sanitizes the request path and parameters, but the data returned by the API is passed to the agent as raw JSON without content-level sanitization.
Audit Metadata