ulta-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to the vendor's API at api.crawlora.net to retrieve product information, categories, and store details. This communication is restricted to the official vendor domain and is the core purpose of the skill.
  • [COMMAND_EXECUTION]: A bash script (scripts/crawlora.sh) acts as a wrapper for curl. It implements strong security controls, including validating the format of the CRAWLORA_API_KEY, whitelisting specific URL paths, and rejecting the '@' character in query arguments to prevent potential local file disclosure through curl's configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches product reviews and customer Q&A from the public Ulta catalog. While this data is external and untrusted, the risk is managed as it is the primary data source for the skill's research function. 1. Ingestion points: Results from the /ulta/product/questions and /ulta/product/reviews endpoints. 2. Boundary markers: No explicit delimiters are used to wrap the API responses. 3. Capability inventory: The skill has network access via the validated helper script. 4. Sanitization: The helper script validates the request path and parameters, although the content of the retailer's catalog data is not altered.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — ulta-research