nike-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a bash helper script (scripts/crawlora.sh) to make API calls. The script is defensively written with features like strict path validation (a static whitelist of Nike endpoints), restriction to the GET method, and validation of the API key format to prevent command injection. It also uses curl's config file feature to pass credentials securely without exposing them in process listings.
- [INDIRECT_PROMPT_INJECTION]: The skill processes JSON data from the Nike catalog (e.g., product descriptions and customer reviews). This creates an indirect prompt injection surface as external content is ingested into the agent context.
- Ingestion points: Catalog data fetched via scripts/crawlora.sh is returned to the agent.
- Boundary markers: The skill does not define explicit delimiters or instructions to the agent to disregard instructions embedded in product metadata or reviews.
- Capability inventory: The skill utilizes curl via a bash script to perform network operations to the api.crawlora.net domain.
- Sanitization: The helper script implements parameter encoding via curl's --data-urlencode and prevents the use of the @ character in arguments, which protects against certain curl-based file access attacks.
Audit Metadata