pinterest-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Pinterest, such as pin descriptions, board metadata, and user bios.
- Ingestion points: Data enters the agent's context through JSON responses from
scripts/crawlora.shcalling Pinterest endpoints. - Boundary markers: The skill does not provide specific instructions or delimiters to help the agent distinguish between its own instructions and the fetched Pinterest content.
- Capability inventory: The skill possesses network read capabilities via
curlinscripts/crawlora.sh. - Sanitization: While the helper script ensures safe HTTP requests, the resulting content (text fields from Pinterest) is passed directly to the agent without filtering for malicious instructions.
- [COMMAND_EXECUTION]: The skill uses
scripts/crawlora.shto executecurlcommands. - The script implements robust input validation, including regex-based path allow-listing and character restrictions on the API key variable.
- It prevents local file disclosure by rejecting the
@character in query parameters and using a temporary configuration file for the API key to avoid command-line exposure. - [DATA_EXFILTRATION]: The skill requires a
CRAWLORA_API_KEYenvironment variable to function. - It communicates with
api.crawlora.netto retrieve Pinterest data. This domain belongs to the skill's vendor (crawlora-org).
Audit Metadata