wayfair-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a bash helper script (
scripts/crawlora.sh) to executecurlandjqfor API interaction and data processing. - The script implements strict security measures including
set -euo pipefailandumask 077for temporary file security. - It performs explicit route whitelisting using anchored regular expressions (e.g.,
^/wayfair/product/[^/]+$) to prevent unauthorized API calls or path traversal attacks. - It validates the format of the
CRAWLORA_API_KEYto prevent injection via the environment variable. - [EXTERNAL_DOWNLOADS]: The skill interacts with the Crawlora API at
https://api.crawlora.net/api/v1to retrieve Wayfair category and product information. - These network operations are limited to the vendor's own infrastructure and are used for the skill's primary purpose of data retrieval.
- API requests are handled securely by passing credentials via a temporary curl configuration file, ensuring the API key does not appear in process listings.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data (product names, brands, descriptions, and categories) from the Wayfair catalog via the Crawlora API.
- Ingestion points: Data enters the agent context through the output of the
scripts/crawlora.shscript. - Boundary markers: The script returns structural JSON data which acts as a natural boundary, though no explicit instructions are provided to the LLM to ignore embedded commands within the text fields.
- Capability inventory: The skill is limited to data retrieval and does not have file-writing or arbitrary code execution capabilities.
- Sanitization: The helper script uses
--data-urlencodeto sanitize outgoing query parameters, but does not provide additional sanitization for the incoming JSON data content.
Audit Metadata