wish-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill follows secure practices for handling API keys by requiring them in environment variables rather than hardcoding them. The helper script
scripts/crawlora.shfurther secures the key by writing it to a temporary configuration file with restricted permissions (chmod 600) and passing it tocurlvia--config, which prevents the key from appearing in process lists (e.g., viapsortop).- [COMMAND_EXECUTION]: The helper scriptscripts/crawlora.shimplements several defensive measures against command injection and unauthorized access. It uses strict path allowlisting for API routes and validates that the API key format matches an expected character set. It also explicitly rejects the@character in query parameters to preventcurlfrom interpreting inputs as local file paths for upload (a common technique for local file disclosure).- [DATA_EXFILTRATION]: Network requests are restricted to the official vendor API endpoint (api.crawlora.net). The script hardcodes the base URL to prevent redirection of sensitive data to attacker-controlled hosts via environment variables.- [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data from Wish, it acts as a passive research tool. The fetched JSON data is intended for information retrieval, and the skill does not expose dangerous capabilities (like file writing or shell execution) that could be exploited by malicious content embedded in product descriptions or reviews.
Audit Metadata