walmart-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/crawlora.sh helper script uses curl to interact with the Crawlora API with several security protections. It stores the API key in a temporary file with owner-only permissions and ensures its deletion on exit, preventing exposure in process lists. It also restricts network requests to a specific whitelist of Walmart-related routes and prevents local file disclosure by rejecting sensitive characters in input parameters.
  • [DATA_EXPOSURE]: The skill manages the CRAWLORA_API_KEY through environment variables, which is a standard and safe method for handling credentials. The helper script ensures the key is never passed as a command-line argument.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Walmart pages through the Crawlora API. This surface is mitigated by the following factors:
  • Ingestion points: Data enters through the /walmart/search and /walmart/product endpoints (found in reference/endpoints.md).
  • Boundary markers: None explicitly defined in the prompt instructions.
  • Capability inventory: The skill possesses network request capabilities via scripts/crawlora.sh to a fixed base URL but lacks file system write access or arbitrary code execution capabilities.
  • Sanitization: The API returns normalized JSON rather than raw HTML, which reduces the complexity of processed content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — walmart-research