retail-assortment-gap-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and analyzes product information (titles, descriptions, and category paths) from external retailers like Shopify, Target, and IKEA via the Crawlora API. This untrusted content serves as a surface for indirect prompt injection.
  • Ingestion points: JSON payloads returned by scripts/crawlora.sh which are then processed by the agent to perform gap analysis.
  • Boundary markers: The instructions in SKILL.md do not specify the use of delimiters or provide "ignore embedded instructions" warnings for the retail data being ingested.
  • Capability inventory: The agent has access to scripts/crawlora.sh, which performs network operations (GET and POST requests via curl) using an API key.
  • Sanitization: Although scripts/crawlora.sh implements defensive coding (including path whitelisting, shell argument sanitization, and preventing curl from reading local files via the @ prefix), the skill does not define sanitization or validation logic for the content returned by the external retail catalogs before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — retail-assortment-gap-analysis