oldnavy-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the Crawlora API (such as product descriptions and customer reviews) which could potentially contain malicious instructions aimed at the agent.
- Ingestion points: Data retrieved from the Old Navy product reviews and search endpoints via the scripts/crawlora.sh helper script.
- Boundary markers: None; the skill instructions do not currently include specific delimiters or directives for the agent to ignore instructions embedded within the retrieved product data.
- Capability inventory: The skill can execute the scripts/crawlora.sh script to perform network operations and uses jq for parsing.
- Sanitization: The skill relies on the API to return structured JSON data, but it does not explicitly sanitize text fields within that data before processing.
Audit Metadata